CVE-2022-31657

VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vmwareCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
vmwareidentity_manager
3.3.4
vmwareidentity_manager
3.3.5
vmwareidentity_manager
3.3.6
vmwareone_access
21.08.0.0
vmwareone_access
21.08.0.1
vmwareaccess_connector
21.08.0.0
vmwareaccess_connector
21.08.0.1
vmwareaccess_connector
22.05
vmwareidentity_manager_connector
3.3.4
vmwareidentity_manager_connector
3.3.5
vmwareidentity_manager_connector
3.3.6
vmwareidentity_manager_connector
19.03.0.1
𝑥
= Vulnerable software versions