Information disclosure in VMware Workspace One Access - CVE-2022-22961
Published: April 6, 2022 / Updated: September 4, 2024
Vulnerability identifier: #VU61936
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22961
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can obtain hostname of the target system.
Affected software
VMware Workspace One Access
VMware Identity Manager
Cloud Foundation
vRealize Suite Lifecycle Manager
VMware Identity Manager
Cloud Foundation
vRealize Suite Lifecycle Manager
How to mitigate CVE-2022-22961
Install updates from vendor's website.