'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2022-22954: VMware Workspace ONE Access Code Injection Vulnerability
Severity:critical
CVE ID:CVE-2022-22954
| Descripiton:
|
VMware Workspace One Access is VMware's technology that combines user identity with factors such as device and network information to make intelligence-driven conditional access decisions for applications delivered by Workspace One. A code injection vulnerability exists in several VMware products that stems from incorrect input validation. A remote attacker could exploit the vulnerability to send a specially crafted HTTP request and perform server-side template injection. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.