Improper Authentication in VMware, Inc products - CVE-2022-31656

 

Improper Authentication in VMware, Inc products - CVE-2022-31656

Published: August 2, 2022 / Updated: August 10, 2022


Vulnerability identifier: #VU65957
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31656
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an error in authentication process affecting local domain users. A remote non-authenticated attacker with access to the UI can bypass authentication process and gain administrative access to the system.


Affected software

VMware Identity Manager
Aria Automation (formerly vRealize Automation)
Cloud Foundation
vRealize Suite Lifecycle Manager
VMware Workspace One Access
Dell Enterprise Hybrid Cloud

How to mitigate CVE-2022-31656

Install updates from vendor's website.

Dell Enterprise Hybrid Cloud - update to 4.1.2

External References

Related Security Bulletins