CVE-2022-22972

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vmwareCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
vmwareidentity_manager
3.3.3
vmwareidentity_manager
3.3.4
vmwareidentity_manager
3.3.5
vmwareidentity_manager
3.3.6
vmwarevrealize_automation
7.6
vmwareworkspace_one_access
20.10.0.0
vmwareworkspace_one_access
20.10.0.1
vmwareworkspace_one_access
21.08.0.0
vmwareworkspace_one_access
21.08.0.1
vmwarecloud_foundation
3.0
vmwarecloud_foundation
3.0.1
vmwarecloud_foundation
3.0.1.1
vmwarecloud_foundation
3.5
vmwarecloud_foundation
3.5.1
vmwarecloud_foundation
3.7
vmwarecloud_foundation
3.7.1
vmwarecloud_foundation
3.7.2
vmwarecloud_foundation
3.8
vmwarecloud_foundation
3.8.1
vmwarecloud_foundation
3.9
vmwarecloud_foundation
3.9.1
vmwarecloud_foundation
3.10
vmwarecloud_foundation
3.10.1
vmwarecloud_foundation
3.10.1.1
vmwarecloud_foundation
3.10.1.2
vmwarecloud_foundation
3.10.2.1
vmwarecloud_foundation
3.10.2.2
vmwarecloud_foundation
3.11
vmwarecloud_foundation
3.11.0.1
vmwarecloud_foundation
4.0
vmwarecloud_foundation
4.0.1
vmwarecloud_foundation
4.1
vmwarecloud_foundation
4.1.0.1
vmwarecloud_foundation
4.2
vmwarecloud_foundation
4.2.1
vmwarecloud_foundation
4.3
vmwarecloud_foundation
4.3.1
vmwarevrealize_suite_lifecycle_manager
8.0
vmwarevrealize_suite_lifecycle_manager
8.0.1
vmwarevrealize_suite_lifecycle_manager
8.1
vmwarevrealize_suite_lifecycle_manager
8.2
vmwarevrealize_suite_lifecycle_manager
8.2:patch1
vmwarevrealize_suite_lifecycle_manager
8.2:patch2
vmwarevrealize_suite_lifecycle_manager
8.2:patch3
vmwarevrealize_suite_lifecycle_manager
8.3
vmwarevrealize_suite_lifecycle_manager
8.3:patch1
vmwarevrealize_suite_lifecycle_manager
8.3:patch2
vmwarevrealize_suite_lifecycle_manager
8.3:patch3
vmwarevrealize_suite_lifecycle_manager
8.4
vmwarevrealize_suite_lifecycle_manager
8.4:patch1
vmwarevrealize_suite_lifecycle_manager
8.4.1
vmwarevrealize_suite_lifecycle_manager
8.4.1:patch1
vmwarevrealize_suite_lifecycle_manager
8.4.1:patch2
vmwarevrealize_suite_lifecycle_manager
8.4.1:patch3
vmwarevrealize_suite_lifecycle_manager
8.6
vmwarevrealize_suite_lifecycle_manager
8.6:patch1
vmwarevrealize_suite_lifecycle_manager
8.6.1
vmwarevrealize_suite_lifecycle_manager
8.6.2
vmwarevrealize_suite_lifecycle_manager
8.7
vmwarevrealize_suite_lifecycle_manager
8.8
𝑥
= Vulnerable software versions