ZeroHour

CVE-2022-22961

CVSS 3.1
5.3 medium
EPSS
<1%p56
Published
()
Modified
Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.

Vendors
vmware
Products
cloud foundation, identity manager, vrealize automation, vrealize suite lifecycle manager, workspace one access
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news