Known vulnerabilities in VMware Workspace One Access 20.10

Vendor: Broadcom
Version: 20.10
Software CPE: cpe:2.3:o:broadcom:vmware_access:*:*:*:*:*:*:*:*
Total vulnerabilities: 13
Public exploits: 4
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting VMware Workspace One Access version 20.10 VMware Workspace One Access 20.10 is affected by 13 vulnerabilities: 3 critical, 2 high, 2 medium, 6 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU61936 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22961
CWE-200 Medium
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040615
and 1 more
#VU61935 - Incorrect Default Permissions
CVE-2022-22960
CWE-276 Low
Public exploit available
Exploited
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61934 - Cross-Site Request Forgery (CSRF)
CVE-2022-22959
CWE-352 High
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61933 - Deserialization of Untrusted Data
CVE-2022-22958
CWE-502 Low
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61932 - Deserialization of Untrusted Data
CVE-2022-22957
CWE-502 Low
Public exploit available
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61931 - Improper Authentication
CVE-2022-22956
CWE-287 Critical
Public exploit available
No
- 06.04.2022 SB2022040612
#VU61930 - Improper Authentication
CVE-2022-22955
CWE-287 Critical
No
No
- 06.04.2022 SB2022040612
#VU61929 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22954
CWE-94 Critical
Public exploit available
Exploited
- 06.04.2022 SB2022040612
SB2022040613
SB2022040615
and 1 more
#VU59055 - Improper Authentication
CVE-2021-22057
CWE-287 Low
No
No
- 20.12.2021 SB2021122001
SB2021122004
#VU59054 - Server-Side Request Forgery (SSRF)
CVE-2021-22056
CWE-918 Low
No
No
- 20.12.2021 SB2021122001
SB2021122002
SB2021122003
#VU55616 - Unprotected primary channel
CVE-2021-22003
CWE-419 Low
No
No
- 05.08.2021 SB2021080524
SB2021080525
SB2021080526
and 2 more
#VU55615 - Server-Side Request Forgery (SSRF)
CVE-2021-22002
CWE-918 High
No
No
- 05.08.2021 SB2021080524
SB2021080525
SB2021080526
and 3 more
#VU48624 - Command injection
CVE-2020-4006
CWE-77 Medium
No
Exploited
- 23.11.2020 SB2020112415