Server-Side Request Forgery (SSRF) in VMware Workspace One Access - CVE-2021-22002

 

Server-Side Request Forgery (SSRF) in VMware Workspace One Access - CVE-2021-22002

Published: August 5, 2021


Vulnerability identifier: #VU55615
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2021-22002
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input in the /cfg web app and diagnostic endpoints. A remote attacker can send a specially crafted HTTP request with a modified HTTP Host header to port 443/TCP and access the /cfg web application, available at port 8443. As a result, a remote non-authenticated attacker can perform SSRF attack and gain access to services in the internal network.


Affected software

VMware Workspace One Access
VMware Identity Manager
Aria Automation (formerly vRealize Automation)
Cloud Foundation
Dell Enterprise Hybrid Cloud
vRealize Suite Lifecycle Manager

How to mitigate CVE-2021-22002

Install updates from vendor's website.

Dell Enterprise Hybrid Cloud - update to 4.1.2

External References

Related Security Bulletins