CVE-2023-20884
30.05.2023, 16:15
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability.An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
Vendor | Product | Version |
---|---|---|
vmware | identity_manager | 3.3.6 |
vmware | identity_manager | 3.3.7 |
vmware | workspace_one_access | 21.0.8.0 ≤ 𝑥 ≤ 22.09.1.0 |
vmware | cloud_foundation | - |
vmware | identity_manager_connector | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration