EXPOSURES › CVE-2022-22954
CVE-2022-22954
CRITICAL ⌖ ON CISA KEV · EXPLOITEDVMware Workspace ONE Access suffered a server-side template injection vulnerability enabling remote code execution and actively exploited by ransomware actors.
A server-side template injection flaw in VMware Workspace ONE Access allowed for remote code execution, which has been actively exploited in the wild, including by ransomware groups. DIB organizations using this product face significant exposure and potential compliance failures (NIST 800-171 controls 3.1.1, 3.1.2, 3.1.3) and should immediately patch or mitigate the vulnerability.
Shame score — The vulnerability's exploitation by ransomware demonstrates a critical failure in secure coding practices and a significant risk to DIB data.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |