imPC@ndo IT

Tracker / CVE-2021-22003

CVE-2021-22003

High 7.5

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

Affected products and versions

vmware cloud_foundation
vmware identity_manager
vmware vrealize_suite_lifecycle_manager
vmware workspace_one_access

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References