VYPR
Unrated severityNVD Advisory· Published Apr 13, 2022· Updated Aug 3, 2024

CVE-2022-22959

CVE-2022-22959

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain a CSRF vulnerability allowing an attacker to trick a user into validating a malicious JDBC URI.

Vulnerability

VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows a malicious actor to trick a user, through a CSRF attack, into unintentionally validating a malicious JDBC URI. Affected products include VMware Workspace ONE Access, Identity Manager (vIDM), vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager. The vulnerability is identified as CVE-2022-22959 and is part of the VMSA-2022-0011 advisory [1].

Exploitation

An attacker can exploit this vulnerability by crafting a request that causes an authenticated user to unknowingly validate a malicious JDBC URI. The attack requires tricking the user to perform actions such as clicking a link or visiting a malicious page. The attacker does not require any special network position beyond delivering the CSRF payload to the victim; the user must be authenticated to the affected VMware product for the exploit to succeed [1].

Impact

Successful exploitation results in the validation of a malicious JDBC URI, which can lead to further compromise. The impact may include disclosure of sensitive information, potential execution of arbitrary SQL commands, or other malicious actions depending on the attacker's payload. The CVSSv3 score for this vulnerability ranges up to 9.8, indicating critical severity [1].

Mitigation

VMware has released patches to remediate this vulnerability. The fixed versions are available in the VMware advisory VMSA-2022-0011.2, updated on April 13, 2022. Users should apply the patches listed in the 'Fixed Version' column of the Resolution Matrix in the advisory. No workarounds were documented specifically for CVE-2022-22959 [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.