7.2
CVSSv3

CVE-2022-22958

Published: 13/04/2022 Updated: 08/08/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware cloud foundation

vmware identity manager 3.3.3

vmware identity manager 3.3.4

vmware identity manager 3.3.5

vmware identity manager 3.3.6

vmware vrealize automation

vmware vrealize automation 7.6

vmware vrealize suite lifecycle manager

vmware workspace one access 20.10.0.0

vmware workspace one access 20.10.0.1

vmware workspace one access 21.08.0.0

vmware workspace one access 21.08.0.1