VYPR
Unrated severityNVD Advisory· Published Aug 5, 2022· Updated Nov 14, 2024

CVE-2022-31659

CVE-2022-31659

Description

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager allows authenticated administrators to execute arbitrary code over the network.

Vulnerability

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability that can be triggered by a malicious actor with administrator and network access. The flaw exists in the affected products prior to the updates released in VMSA-2022-0021. [1]

Exploitation

An attacker with administrative privileges and network connectivity can exploit this vulnerability by sending specially crafted requests to the vulnerable service. No additional user interaction is required beyond the attacker's own authenticated access. The advisory classifies the attack vector as network-based with high complexity due to the privilege requirement. [1]

Impact

Successful exploitation allows the attacker to execute arbitrary code on the affected system, potentially leading to full compromise of the Workspace ONE Access or Identity Manager appliance. This could result in unauthorized access to sensitive data, modification of system configurations, or lateral movement within the VMware infrastructure. [1]

Mitigation

VMware has released software updates to remediate this vulnerability. The fixed versions are detailed in VMSA-2022-0021, with the advisory updated on August 9, 2022. Users should apply the latest patches for Workspace ONE Access, Identity Manager, and related components. No workarounds are provided in the advisory. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.