ZeroHour

CVE-2023-20884

CVSS 3.1
6.1 medium
EPSS
<1%p28
Published
()
Modified
Description

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

Vendors
vmware
Products
identity manager, workspace one access, cloud foundation, identity manager connector
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.