SQL injection in VMware Workspace One Access - CVE-2022-31659
Published: August 2, 2022
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote privileged user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
VMware Identity Manager
Aria Automation (formerly vRealize Automation)
Cloud Foundation
vRealize Suite Lifecycle Manager
Dell Enterprise Hybrid Cloud
How to mitigate CVE-2022-31659
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware Workspace ONE Access
- Multiple vulnerabilities in VMware Identity Manager (vIDM)
- Multiple vulnerabilities in VMware vRealize Automation
- Multiple vulnerabilities in VMware Cloud Foundation (vIDM)
- Multiple vulnerabilities in vRealize Suite Lifecycle Manager
- Multiple vulnerabilities in Dell Enterprise Hybrid Cloud