Skip to content
COOEY

EXPOSURES › CVE-2022-22954

CVE-2022-22954

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-14 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-22954 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

VMware Workspace ONE Access suffered a server-side template injection vulnerability enabling remote code execution and actively exploited by ransomware actors.

A server-side template injection flaw in VMware Workspace ONE Access allowed for remote code execution, which has been actively exploited in the wild, including by ransomware groups. DIB organizations using this product face significant exposure and potential compliance failures (NIST 800-171 controls 3.1.1, 3.1.2, 3.1.3) and should immediately patch or mitigate the vulnerability.

Shame score — The vulnerability's exploitation by ransomware demonstrates a critical failure in secure coding practices and a significant risk to DIB data.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized