Junglewise Threat Intelligence

CVE-2022-22954: VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

CVE-2022-22954 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-14

Technologies: VMware Identity Manager, VMware Workspace ONE Access. Vendors: VMware.

Executive brief

VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger this injection to execute arbitrary commands on the server.

Affected products

  • VMware Workspace ONE Access 20.10.0.0, 20.10.0.1, 21.08.0.0, 21.08.0.1
  • VMware Identity Manager 3.3.3, 3.3.4, 3.3.5, 3.3.6
  • VMware vRealize Automation 7.6, 8.0 through 8.6

Timeline

  • 2022-04-06: advisory: Initial vendor advisory VMSA-2022-0011 published by VMware
  • 2022-04-14: disclosed: CVE published in NVD
  • 2022-04-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-14: exploited: Reported as exploited in the wild