Rapid7 Vulnerability & Exploit Database

VMware Workspace ONE Access: CVE-2021-22003: Information Disclosure Vulnerability in VMware Workspace One Access (VMSA-2021-0016)

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

VMware Workspace ONE Access: CVE-2021-22003: Information Disclosure Vulnerability in VMware Workspace One Access (VMSA-2021-0016)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
08/31/2021
Created
09/25/2021
Added
09/24/2021
Modified
01/09/2024

Description

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

Solution(s)

  • vmware-workspace-one-access-upgrade-20_01_0_0_17267236
  • vmware-workspace-one-access-upgrade-20_10_01_0_17267238
  • vmware-workspace-one-access-upgrade-20_10_0_0_17267237

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;