Input validation error in VMware Workspace One Access - CVE-2022-31700
Published: December 14, 2022
Vulnerability identifier: #VU70300
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31700
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote authenticated administrator can pass specially crafted input to the application and execute arbitrary code on the system.
Affected software
VMware Workspace One Access
VMware Identity Manager
VMware Identity Manager
How to mitigate CVE-2022-31700
Install updates from vendor's website.
VMware Workspace One Access - update to 22.09.1.0