ZeroHour

CVE-2022-31656

CVSS 3.1
9.8 critical
EPSS
23%p98
Published
()
Modified
Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Vendors
vmware
Products
identity manager, one access, access connector, identity manager connector
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news