CVE-2021-22056

EUVD-2021-9221
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
vmwareidentity_manager
3.3.3
vmwareidentity_manager
3.3.4
vmwareidentity_manager
3.3.5
vmwarevrealize_automation
8.0 ≤
𝑥
≤ 8.6
vmwarevrealize_automation
7.6
vmwareworkspace_one_access
20.10
vmwareworkspace_one_access
20.10.01
vmwareworkspace_one_access
21.08
vmwareworkspace_one_access
21.08.01
𝑥
= Vulnerable software versions