vulnerability

VMware Workspace ONE Access: CVE-2022-22959: Cross Site Request Forgery Vulnerability (VMSA-2022-0011)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Apr 11, 2022
Added
Apr 11, 2022
Modified
Aug 11, 2025

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.

Solutions

vmware-workspace-one-access-upgrade-20_10_0_0_17035009vmware-workspace-one-access-upgrade-20_10_0_1_17586971vmware-workspace-one-access-upgrade-21_08_0_0_18530336vmware-workspace-one-access-upgrade-21_08_0_1_19010796
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.