Improper Authentication in Broadcom products - CVE-2022-22972

 

Improper Authentication in Broadcom products - CVE-2022-22972

Published: May 18, 2022 / Updated: May 29, 2022


Vulnerability identifier: #VU63406
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22972
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the UI when processing authentication requests. A remote attacker can bypass authentication process and gain administrative access to the application.


Affected software

VMware Identity Manager
Aria Automation (formerly vRealize Automation)
Cloud Foundation
vRealize Suite Lifecycle Manager
VMware Workspace One Access

How to mitigate CVE-2022-22972

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins