ZeroHour

CVE-2022-31657

CVSS 3.1
9.8 critical
EPSS
1%p69
Published
()
Modified
Description

VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.

Vendors
vmware
Products
identity manager, one access, access connector, identity manager connector
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news