VYPR
Medium severity6.1NVD Advisory· Published May 30, 2023· Updated Jun 17, 2026

CVE-2023-20884

CVE-2023-20884

Description

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:a:vmware:cloud_foundation:-:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:identity_manager:3.3.7:*:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:a:vmware:identity_manager_connector:*:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:workspace_one_access:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:vmware:workspace_one_access:*:*:*:*:*:*:*:*range: >=21.0.8.0,<=22.09.1.0
    • (no CPE)
  • VMware/Workspace ONE Accessdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.