ZeroHour

CVE-2022-31663

CVSS 3.1
6.1 medium
EPSS
<1%p49
Published
()
Modified
Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.

Vendors
vmware
Products
identity manager, one access, access connector, identity manager connector
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news