Executive brief
VMware Workspace One Access, Identity Manager, and related connectors contain a command injection vulnerability in the administrative configurator on port 8443. An authenticated attacker with a valid configurator administrator password can execute arbitrary commands with unrestricted privileges on the underlying operating system.
Affected products
- VMware Workspace One Access 20.01, 20.10
- VMware Identity Manager 3.3.1, 3.3.2, 3.3.3
- VMware Identity Manager Connector 3.3.1, 3.3.2, 3.3.3
- VMware Cloud Foundation 4.0, 4.0.1
- VMware vRealize Suite Lifecycle Manager 8.0 through 8.2
Timeline
- 2020-11-23: disclosed: Initial NVD publication date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed as exploited in the wild per CISA KEV entry