Unrated severityCISA KEVNVD Advisory· Published Apr 11, 2022· Updated Oct 21, 2025
CVE-2022-22954
CVE-2022-22954
Description
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
Affected products
1- VMware/Workspace ONE Access and Identity Managerdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injection-Command-Execution.htmlmitrex_refsource_MISC
- www.vmware.com/security/advisories/VMSA-2022-0011.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.