Main
Vulnerability Database
Exploits
ID:7897 - Exploit for Improper Authentication in VMware, Inc products - CVE-2022-22972
ID:7897 - Exploit for Improper Authentication in VMware, Inc products - CVE-2022-22972
Published: May 26, 2022
Vulnerability identifier: #VU63406
Vulnerability risk: High
CVE-ID: CVE-2022-22972
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
VMware Workspace One Access
VMware Identity Manager
Aria Automation (formerly vRealize Automation)
Cloud Foundation
vRealize Suite Lifecycle Manager
VMware Workspace One Access
VMware Identity Manager
Aria Automation (formerly vRealize Automation)
Cloud Foundation
vRealize Suite Lifecycle Manager
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the UI when processing authentication requests. A remote attacker can bypass authentication process and gain administrative access to the application.
Remediation
Install updates from vendor's website.