CVE-2022-22961

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vrealize_automation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vrealize_automation:7.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workspace_one_access:20.10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workspace_one_access:20.10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workspace_one_access:21.08.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workspace_one_access:21.08.0.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-668 CWE-200

21 Apr 2022, 16:37

Type Values Removed Values Added
First Time Vmware cloud Foundation
Vmware vrealize Suite Lifecycle Manager
Vmware identity Manager
Linux linux Kernel
Vmware vrealize Automation
Vmware
Linux
Vmware workspace One Access
CPE cpe:2.3:a:vmware:vrealize_automation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workspace_one_access:20.10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workspace_one_access:20.10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workspace_one_access:21.08.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vrealize_automation:7.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workspace_one_access:21.08.0.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:*:*:*:*:*:*:*:*
CWE CWE-668
References (MISC) https://www.vmware.com/security/advisories/VMSA-2022-0011.html - (MISC) https://www.vmware.com/security/advisories/VMSA-2022-0011.html - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3

13 Apr 2022, 18:55

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-13 18:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-22961

Mitre link : CVE-2022-22961

CVE.ORG link : CVE-2022-22961


JSON object : View

Products Affected

vmware

  • cloud_foundation
  • vrealize_automation
  • vrealize_suite_lifecycle_manager
  • workspace_one_access
  • identity_manager

linux

  • linux_kernel
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor