Code Injection in VMware Workspace One Access - CVE-2022-22954
Published: April 6, 2022 / Updated: September 4, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted HTTP request and perform server-side template injection.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
VMware Identity Manager
Cloud Foundation
vRealize Suite Lifecycle Manager
How to mitigate CVE-2022-22954
Links to Public Exploits and PoC-codes
- Exploit #9166 - CVE-2022-22954-VMware-RCE (CVE-2022-22954-VMware-RCE批量检测POC) (June 29, 2023)
- Exploit #8627 - CVE-2022-22954 () (November 22, 2022)
- Exploit #8615 - CVE-2022-22954-POC () (November 17, 2022)
- Exploit #8540 - CVE-2022-22954_ () (October 26, 2022)
- Exploit #7981 - CVE-2022-22954 (VMware Workspace ONE Access and Identity Manager RCE via SSTI. CVE-2022-22954 - PoC SSTI * exploit+payload+shodan (ну набором)) (June 6, 2022)
- Exploit #7976 - CVE-2022-22954-VMware-RCE (CVE-2022-22954-VMware-RCE批量检测POC) (June 6, 2022)
- Exploit #7971 - CVE-2022-22954 () (June 6, 2022)
- Exploit #7952 - CVE-2022-22954_ () (June 2, 2022)
- Exploit #7939 - CVE-2022-22954 () (June 1, 2022)
- Exploit #7784 - VMware Workspace ONE Access CVE-2022-22954 (May 12, 2022)
- Exploit #7716 - VMware Workspace ONE Access Template Injection / Command Execution (May 4, 2022)
- Exploit #7666 - CVE-2022-22954 (CVE-2022-22954 VMware Workspace ONE Access free marker SSTI) (April 18, 2022)
- Exploit #7665 - vmware4shell (CVE 2022-22954 - VMWare Workspace ONE Acess SSTI) (April 18, 2022)
- Exploit #7656 - VMware-CVE-2022-22954-Command-Injector (Proof of Concept for exploiting VMware CVE-2022-22954) (April 15, 2022)
- Exploit #7655 - CVE-2022-22954-POC () (April 15, 2022)
- Exploit #7642 - CVE-2022-22954 (VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng) (April 14, 2022)
- Exploit #7641 - CVE-2022-22954_VMware_PoC (PoC for CVE-2022-22954 - VMware Workspace ONE Access Freemarker Server-Side Template Injection) (April 14, 2022)
- Exploit #7639 - CVE-2022-22954-PoC (VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual. ) (April 14, 2022)
- Exploit #7638 - CVE-2022-22954 (CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入) (April 14, 2022)
- Exploit #7634 - CVE-2022-22954-POC (提供单个或批量URL扫描是否存在CVE-2022-22954功能) (April 12, 2022)
- Exploit #7632 - CVE-2022-22954 (提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码) (April 12, 2022)
- Exploit #7631 - CVE-2022-22954-VMware-RCE (CVE-2022-22954-VMware-RCE批量检测POC) (April 12, 2022)
- Exploit #7630 - VMware-CVE-2022-22954 () (April 12, 2022)
- Exploit #7629 - CVE-2022-22954 () (April 12, 2022)
- Exploit #7628 - CVE-2022-22954-Testi (CVE-2022-22954 Açığı test etme) (April 12, 2022)
- Exploit #7625 - VMware-CVE-2022-22954 (POC for VMWARE CVE-2022-22954) (April 11, 2022)
- Exploit #7624 - VMWare_CVE-2022-22954 (CVE-2022-22954 is a server-side template injection vulnerability in the VMware Workspace ONE Access and Identity Manager) (April 11, 2022)