VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2022-0021.html | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Configuration 2 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2022-08-05 09:15
Updated : 2022-08-11 09:05
NVD link : CVE-2022-31657
Mitre link : CVE-2022-31657
JSON object : View
CWE
                
                    
                        
                        CWE-74
                        
            Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
                microsoft
- windows
 
vmware
- access_connector
 - identity_manager_connector
 - one_access
 - identity_manager
 
linux
- linux_kernel
 


