Vulnerabilities
Vulnerable Software
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
CVSS Score
9.8
EPSS Score
0.569
Published
2022-04-13
CVE-2022-22954
Known exploited
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
CVSS Score
9.8
EPSS Score
0.944
Published
2022-04-11


Contact Us

Shodan ® - All rights reserved