CVE Database
/

CVE-2022-22954

Back to search

CVE-2022-22954

Published: Apr 11, 2022

Modified: Oct 21, 2025

PUBLISHED

Description

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

VendorProductVersions

n/a

VMware Workspace ONE Access and Identity Manager

affected
Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0. Identity Manager 3.3.6, 3.3.5, 3.3.4, 3.3.3.

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now