Description
This module combines two vulnerabilities in order achieve remote code execution in the context of the `horizon` user. The first vulnerability CVE-2022-22956 is an authentication bypass in OAuth2TokenResourceController ACS which allows a remote, unauthenticated attacker to bypass the authentication mechanism and execute any operation. The second vulnerability CVE-2022-22957 is a JDBC injection RCE specifically in the DBConnectionCheckController class's dbCheck method which allows an attacker to deserialize arbitrary Java objects which can allow remote code execution.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/vmware/workspace_one_access_vmsa_2022_0011_chainmsf undefined(workspace_one_access_vmsa_2022_0011_chain) > show actions ...actions...msf undefined(workspace_one_access_vmsa_2022_0011_chain) > set ACTION < action-name >msf undefined(workspace_one_access_vmsa_2022_0011_chain) > show options ...show and set options...msf undefined(workspace_one_access_vmsa_2022_0011_chain) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub