Code Injection in VMware Workspace One Access - CVE-2022-31658
Published: August 2, 2022
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when handling JDBC string. A remote privileged user can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
VMware Identity Manager
Aria Automation (formerly vRealize Automation)
Cloud Foundation
vRealize Suite Lifecycle Manager
Dell Enterprise Hybrid Cloud
How to mitigate CVE-2022-31658
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware Workspace ONE Access
- Multiple vulnerabilities in VMware Identity Manager (vIDM)
- Multiple vulnerabilities in VMware vRealize Automation
- Multiple vulnerabilities in VMware Cloud Foundation (vIDM)
- Multiple vulnerabilities in vRealize Suite Lifecycle Manager
- Multiple vulnerabilities in Dell Enterprise Hybrid Cloud