Input validation error in VMware Workspace One Access - CVE-2022-31700

 

Input validation error in VMware Workspace One Access - CVE-2022-31700

Published: December 14, 2022


Vulnerability identifier: #VU70300
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31700
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote authenticated administrator can pass specially crafted input to the application and execute arbitrary code on the system.


Affected software

VMware Workspace One Access
VMware Identity Manager

How to mitigate CVE-2022-31700

Install updates from vendor's website.

VMware Workspace One Access - update to 22.09.1.0

External References

Related Security Bulletins