ZeroHour

CVE-2022-22972

CVSS 3.1
9.8 critical
EPSS
56%p99
Published
()
Modified
Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Vendors
vmware
Products
identity manager, vrealize automation, workspace one access, cloud foundation, vrealize suite lifecycle manager
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news