CVE-2022-31663
Description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
VMware Workspace ONE Access, Identity Manager, and vRealize Automation are vulnerable to reflected XSS via improper input sanitization, requiring user interaction to inject arbitrary JavaScript.
Vulnerability
CVE-2022-31663 is a reflected cross-site scripting (XSS) vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation. The flaw stems from improper sanitization of user-supplied input, allowing injection of arbitrary JavaScript code into a target user's browser window [1]. Affected versions include VMware Workspace ONE Access (Access), Workspace ONE Access Connector (Access Connector), Identity Manager (vIDM), Identity Manager Connector, and VMware vRealize Automation, as listed in advisory VMSA-2022-0021 [1].
Exploitation
An attacker must trick a victim into clicking a crafted link or visiting a specially crafted URL that reflects malicious input back to the user. No privileged network position is required, but successful exploitation depends on user interaction—the victim must click the attacker-controlled link. The attack is reflected, so the malicious payload is not stored on the server; it executes only when the victim follows the crafted URL [1].
Impact
A successful attack enables the attacker to execute arbitrary JavaScript code in the context of the victim's browser session. This can lead to information disclosure, session hijacking, or actions performed on behalf of the victim with the privileges of the affected application. The scope is the victim's browser session within the vulnerable VMware application [1].
Mitigation
VMware released fixed versions in advisory VMSA-2022-0021, with updates available for Workspace ONE Access (21.08.0.1, 21.08.0.2), Access Connector (21.08.0.1, 21.08.0.2), Identity Manager (3.3.7, 3.3.8), Identity Manager Connector (3.3.7, 3.3.8), and vRealize Automation 7.6 and 8.x series. Users should apply the latest patches as detailed in the advisory [1]. No workarounds are provided; upgrading is the only mitigation.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- VMware/Workspace ONE Access, Identity Manager and vRealize Automationdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.vmware.com/security/advisories/VMSA-2022-0021.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.