Path traversal in VMware Workspace One Access - CVE-2022-31662

 

Path traversal in VMware Workspace One Access - CVE-2022-31662

Published: August 2, 2022


Vulnerability identifier: #VU65988
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31662
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

VMware Workspace One Access
VMware Identity Manager
Aria Automation (formerly vRealize Automation)
VMware Identity Manager Connector
Cloud Foundation
vRealize Suite Lifecycle Manager
Dell Enterprise Hybrid Cloud

How to mitigate CVE-2022-31662

Install update from vendor's website.

Dell Enterprise Hybrid Cloud - update to 4.1.2

External References

Related Security Bulletins