CVE-2022-22956
Description
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
In plain language
AI Act nowCVE-2022-22956 is an authentication-bypass flaw in VMware Workspace ONE Access—if your server’s OAuth2 authentication endpoints are reachable from the network, a remote attacker can log in without credentials and take over operations; this is a serious RED situation for affected businesses.
CVE-2022-22956 is an unauthenticated authentication-bypass in VMware Workspace ONE Access’s OAuth2 ACS framework via exposed authentication endpoints, allowing an attacker to bypass the authentication check and execute unauthorized operations.
What to do now
- Check whether you run VMware Workspace ONE Access (including its related identity/connector components) and whether the OAuth2 ACS/authentication endpoints are reachable from the network.
- Compare your installed version to the vendor’s fixed release guidance; at minimum, ensure the impacted vrealize automation component is updated to a fixed level.
- Upgrade to the fixed version(s) listed by VMware; for vrealize automation, apply the fix so it is “fixed in 9.0”.
- If you cannot patch immediately, restrict network access so only trusted internal systems can reach the Workspace ONE Access OAuth2 authentication endpoints (block public reachability and limit inbound to required sources).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2022-22956 and every CVE in our database. Create a free account — no credit card required.
Create Free Account