Tracker / CVE-2022-22956
CVE-2022-22956
Critical 9.8
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Affected products and versions
| vmware | identity_manager |
|---|---|
| vmware | vrealize_automation |
| vmware | vrealize_automation · 8.0 → 9.0 |
| vmware | workspace_one_access |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.