CVE-2022-22957
Description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain a remote code execution vulnerability via JDBC URI deserialization by an admin attacker.
Vulnerability
CVE-2022-22957 is a remote code execution vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation (also affecting VMware Cloud Foundation and vRealize Suite Lifecycle Manager). The vulnerability arises from deserialization of untrusted data through a malicious JDBC URI. A malicious actor with administrative access can exploit this to achieve remote code execution [1].
Exploitation
To exploit, an attacker must have administrative access to the targeted system. The attacker crafts a malicious JDBC URI that triggers deserialization of attacker-controlled data. No user interaction is required beyond the attacker's admin credentials [1].
Impact
Successful exploitation results in remote code execution with the privileges of the application server, leading to full compromise of the affected system, including confidentiality, integrity, and availability [1].
Mitigation
VMware has released patches to address this vulnerability. Customers should apply the updates listed in VMSA-2022-0011.2 for the affected products. No workaround is documented; patching is the only mitigation [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- VMware/Workspace ONE Accessdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.