CVEs (28)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 3Identity Manager Vrealize AutomationWorkspace One AccessJun 17, 2026 Apr 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation...Show more |
1Vmware 5Cloud Foundation Identity ManagerVrealize Automation+2 moreJun 17, 2026 Apr 11, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection tha...Show more |
1Vmware 3Identity Manager Vrealize AutomationWorkspace One AccessJun 17, 2026 Dec 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary ori...Show more |
1Vmware 4Cloud Foundation Identity ManagerVrealize Suite Lifecycle Manager+1 moreJun 17, 2026 Aug 31, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint,...Show more |
1Vmware 4Cloud Foundation Identity ManagerVrealize Suite Lifecycle Manager+1 moreJun 17, 2026 Aug 31, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 c...Show more |
1Vmware 5Cloud Foundation Identity ManagerIdentity Manager Connector+2 moreJun 17, 2026 Nov 23, 2020 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
1Vmware 2Identity Manager Vrealize AutomationMay 6, 2026 Dec 29, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors. |
1Vmware 2Identity Manager Vrealize AutomationMay 6, 2026 Aug 31, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors. |