Cross-site request forgery in VMware Workspace One Access - CVE-2022-22959

 

Cross-site request forgery in VMware Workspace One Access - CVE-2022-22959

Published: April 6, 2022 / Updated: September 4, 2024


Vulnerability identifier: #VU61934
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22959
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website and unintentionally validate a malicious JDBC URI.


Affected software

VMware Workspace One Access
Cloud Foundation
VMware Identity Manager
Aria Automation (formerly vRealize Automation)
vRealize Suite Lifecycle Manager
Dell Enterprise Hybrid Cloud

How to mitigate CVE-2022-22959

Install updates from vendor's website.

Dell Enterprise Hybrid Cloud - update to 4.1.2

External References

Related Security Bulletins