VYPR

Vrealize Automation

by VMware

CVEs (28)

  • CVE-2022-22954CriKEVApr 11, 2022
    risk 0.93cvss 9.8epss 1.00

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

  • CVE-2022-22956CriApr 13, 2022
    risk 0.71cvss 9.8epss 0.51

    VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

  • CVE-2022-22960HigKEVApr 13, 2022
    risk 0.69cvss 7.8epss 0.36

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

  • CVE-2022-22972CriMay 20, 2022
    risk 0.68cvss 9.8epss 0.56

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

  • CVE-2022-31656CriAug 5, 2022
    risk 0.65cvss 9.8epss 0.23

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

  • CVE-2022-22955CriApr 13, 2022
    risk 0.64cvss 9.8epss 0.08

    VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

  • CVE-2018-6959CriApr 13, 2018
    risk 0.64cvss 9.8epss 0.02

    VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.

  • CVE-2017-4947CriJan 29, 2018
    risk 0.64cvss 9.8epss 0.09

    VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.

  • CVE-2016-5336CriAug 31, 2016
    risk 0.64cvss 9.8epss 0.03

    VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2016-7460CriDec 29, 2016
    risk 0.59cvss 9.1epss 0.02

    The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in…

  • CVE-2023-20855HigFeb 22, 2023
    risk 0.57cvss 8.8epss 0.01

    VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information…

  • CVE-2022-31660HigAug 5, 2022
    risk 0.54cvss 7.8epss 0.01

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

  • CVE-2022-22957HigApr 13, 2022
    risk 0.52cvss 7.2epss 0.23

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…

  • CVE-2022-31664HigAug 5, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

  • CVE-2022-31661HigAug 5, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.

  • CVE-2016-5335HigAug 31, 2016
    risk 0.51cvss 7.8epss 0.00

    VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.

  • CVE-2022-31662HigAug 5, 2022
    risk 0.49cvss 7.5epss 0.01

    VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files.

  • CVE-2021-22056HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.02

    VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.

  • CVE-2022-31665HigAug 5, 2022
    risk 0.47cvss 7.2epss 0.02

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

  • CVE-2022-31658HigAug 5, 2022
    risk 0.47cvss 7.2epss 0.02

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

Page 1 of 2