CVE-2022-31663
05.08.2022, 16:15
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
Vendor | Product | Version |
---|---|---|
vmware | identity_manager | 3.3.4 |
vmware | identity_manager | 3.3.5 |
vmware | identity_manager | 3.3.6 |
vmware | one_access | 21.08.0.0 |
vmware | one_access | 21.08.0.1 |
vmware | access_connector | 21.08.0.0 |
vmware | access_connector | 21.08.0.1 |
vmware | access_connector | 22.05 |
vmware | identity_manager_connector | 3.3.4 |
vmware | identity_manager_connector | 3.3.5 |
vmware | identity_manager_connector | 3.3.6 |
vmware | identity_manager_connector | 19.03.0.1 |
𝑥
= Vulnerable software versions