S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-31656 Scanner

CVE-2022-31656 scanner - Authentication Bypass vulnerability in VMware Workspace ONE Access, Identity Manager and vRealize Automation

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-31656
9.8
CVSS

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
VMware Workspace ONE Access, Identity Manager and vRealize Automationby n/a
Workspace One Access (21.08.0.1 & 21.08.0.0), Identity Manager (vIDM) (3.3.6, 3.3.5 & 3.3.4), and vRealize Automation 7.6
Updated Aug 22, 2026View on NVD →
Detail

VMware Workspace ONE Access, Identity Manager, and vRealize Automation are powerful enterprise software solutions designed to streamline access management and automate IT tasks. These products are used by organizations around the world for various purposes such as providing secure access to applications and data, managing user authentication, and automating the process of provisioning and managing virtual infrastructure.

Recently, a critical vulnerability was detected in these products, marked with the CVE-2022-31656. This authentication bypass vulnerability affects local domain users and can allow a malicious actor with network access to the UI to obtain administrative access without the need to authenticate. This security flaw poses a significant threat to any organization that relies on these products as it could result in unauthorized access, data breaches, and system compromise.

If exploited, this vulnerability could lead to devastating consequences for an organization. The attackers might be able to gain access to sensitive information, carry out unauthorized actions, modify critical settings, and cause damage to the system. This could put both the organization and its clients at risk of financial and reputational loss.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability management services that can help organizations identify, prioritize, and mitigate security risks within their systems. With its advanced scanning capabilities and threat intelligence, s4e.io can ensure that critical vulnerabilities like CVE-2022-31656 are promptly detected and addressed, helping organizations keep their digital assets safe and secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are a few precautions that can be taken by organizations. These include:

  • Updating the product to the latest version as soon as possible.
  • Applying available patches and security updates.
  • Reviewing access policies and permissions.
  • Limiting access to sensitive areas of the system.
  • Deploying security monitoring tools to detect any unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-31656 scanner - Authentication Bypass vulnerability in VMware Workspace ONE Access, Identity Manager and vRealize Automation | S4E