← back
CVE-2022-22972observed exploitation

CVE-2022-22972

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 56%
from disclosure to weapon4 days
Published on NVDMay 20
1st PoC+4d
VulnCheckAug 12
exploitation probability
56%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.