VYPR
Unrated severityNVD Advisory· Published Aug 5, 2022· Updated Aug 3, 2024

CVE-2022-31656

CVE-2022-31656

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authentication bypass in VMware Workspace ONE Access, Identity Manager, and vRealize Automation allows unauthenticated administrative access.

Vulnerability

VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. The bug allows a malicious actor with network access to the UI to obtain administrative access without needing to authenticate. The affected versions are those prior to the patches released in VMSA-2022-0021 [1].

Exploitation

An attacker needs only network access to the administrative UI of the affected product. No prior authentication or user interaction is required. By exploiting the authentication bypass, the attacker can gain administrative privileges directly.

Impact

Successful exploitation grants the attacker full administrative access to the affected system. This can lead to complete compromise of confidentiality, integrity, and availability of the application and potentially the underlying infrastructure.

Mitigation

VMware has released security updates to address this vulnerability as part of VMSA-2022-0021. Administrators should apply the relevant patches as soon as possible. No workarounds have been provided. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.