Improper Authentication in VMware Workspace One Access - CVE-2021-22057
Published: December 20, 2021
Vulnerability identifier: #VU59055
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22057
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing 2FA authentication. A remote attacker can obtain the second-factor authentication provided by VMware Verify and gain unauthorized access to the application.
Affected software
VMware Workspace One Access
vRealize Suite Lifecycle Manager
vRealize Suite Lifecycle Manager
How to mitigate CVE-2021-22057
Install updates from vendor's website.