Improper Authentication in VMware, Inc products - CVE-2022-31656
Published: August 2, 2022 / Updated: August 10, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to an error in authentication process affecting local domain users. A remote non-authenticated attacker with access to the UI can bypass authentication process and gain administrative access to the system.
Affected software
Aria Automation (formerly vRealize Automation)
Cloud Foundation
vRealize Suite Lifecycle Manager
VMware Workspace One Access
Dell Enterprise Hybrid Cloud