CVE-2022-22972
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 56%
from disclosure to weapon4 days
Published on NVDMay 20
1st PoC+4d
VulnCheckAug 12
exploitation probability
56%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
public PoCs found — 2
vulncheckvulncheck.com/xdb/9f9e7e157714unverifiedvulncheckvulncheck.com/xdb/4f4f349b8c5cunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.