VYPR
Unrated severityNVD Advisory· Published May 30, 2023· Updated Jan 10, 2025

CVE-2023-20884

CVE-2023-20884

Description

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated attacker can redirect victims to an attacker-controlled domain via improper path handling in VMware Workspace ONE Access and Identity Manager, leading to sensitive information disclosure.

Vulnerability

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability (CVE-2023-20884) due to improper path handling. An unauthenticated attacker can exploit this by crafting a malicious URL that redirects a victim to an attacker-controlled domain. Affected versions include VMware Workspace ONE Access and VMware Identity Manager prior to the fixed versions listed in VMSA-2023-0011 [1].

Exploitation

An attacker with network access to the affected service can send a specially crafted link to a victim. No authentication is required. The victim, upon clicking the link, is redirected to an attacker-controlled domain due to the improper path handling. The attacker does not need any special privileges or user interaction beyond the victim clicking the link [1].

Impact

Successful exploitation allows the attacker to redirect the victim to a malicious domain, potentially leading to sensitive information disclosure. This could include OAuth tokens, session cookies, or other credentials that the victim's browser may send to the attacker-controlled site. The impact is limited to information disclosure; no code execution or privilege escalation is achieved [1].

Mitigation

VMware has released updates to address this vulnerability as part of VMSA-2023-0011. Administrators should apply the latest patches to VMware Workspace ONE Access and VMware Identity Manager. No workarounds are available. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the advisory date [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.