VMware / Identity Manager
28 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-20884 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect… | MEDIUM | 6.1 | May 30, 2023 |
| CVE-2022-31700 | VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue… | HIGH | 7.2 | Dec 14, 2022 |
| CVE-2022-31657 | VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authen… | CRITICAL | 9.8 | Aug 5, 2022 |
| CVE-2022-31656 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious… | CRITICAL | 9.8 | Aug 5, 2022 |
| CVE-2022-31658 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and n… | HIGH | 7.2 | Aug 5, 2022 |
| CVE-2022-31661 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can… | HIGH | 7.8 | Aug 5, 2022 |
| CVE-2022-31659 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can tri… | HIGH | 7.2 | Aug 5, 2022 |
| CVE-2022-31663 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input… | MEDIUM | 6.1 | Aug 5, 2022 |
| CVE-2022-31664 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can esc… | HIGH | 7.8 | Aug 5, 2022 |
| CVE-2022-31665 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and n… | HIGH | 7.2 | Aug 5, 2022 |
| CVE-2022-31660 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can es… | HIGH | 7.8 | Aug 5, 2022 |
| CVE-2022-31662 | VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access… | HIGH | 7.5 | Aug 5, 2022 |
| CVE-2022-22972 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious… | CRITICAL | 9.8 | May 20, 2022 |
| CVE-2022-22973 | VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to '… | HIGH | 7.8 | May 20, 2022 |
| CVE-2022-22958 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A ma… | HIGH | 7.2 | Apr 13, 2022 |
| CVE-2022-22955 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may… | CRITICAL | 9.8 | Apr 13, 2022 |
| CVE-2022-22961 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A ma… | MEDIUM | 5.3 | Apr 13, 2022 |
| CVE-2022-22959 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user th… | MEDIUM | 4.3 | Apr 13, 2022 |
| CVE-2022-22960 KEV | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scrip… | HIGH | 7.8 | Apr 13, 2022 |
| CVE-2022-22957 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A ma… | HIGH | 7.2 | Apr 13, 2022 |
| CVE-2022-22956 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may… | CRITICAL | 9.8 | Apr 13, 2022 |
| CVE-2022-22954 KEV | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with ne… | CRITICAL | 9.8 | Apr 11, 2022 |
| CVE-2021-22056 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with netw… | HIGH | 7.5 | Dec 20, 2021 |
| CVE-2021-22003 | VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 ma… | HIGH | 7.5 | Aug 31, 2021 |
| CVE-2021-22002 | VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom hos… | CRITICAL | 9.8 | Aug 31, 2021 |
Showing 1 to 25 of 28 CVEs