S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-22954 Scanner

CVE-2022-22954 scanner - Server Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access and Identity Manager

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-22954
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
VMware Workspace ONE Access and Identity Managerby n/a
Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0. Identity Manager 3.3.6, 3.3.5, 3.3.4, 3.3.3.
Updated Aug 22, 2026View on NVD →
Detail

VMware Workspace ONE Access and Identity Manager are two separate products that, when used together, provide organizations with an effective and streamlined solution for managing access to their digital assets, including web applications, cloud resources, and mobile devices. VMware Workspace ONE Access provides single sign-on (SSO) capabilities, enabling users to access their applications with a single set of credentials, while VMware Workspace ONE Identity Manager acts as a centralized directory service, providing IT administrators with the necessary tools to manage user identities and access rights.

Recently, a critical vulnerability identified as CVE-2022-22954 has been discovered in these products. The vulnerability affects both VMware Workspace ONE Access and Identity Manager, and can allow a remote attacker to execute arbitrary code on affected systems. Specifically, the vulnerability lies in the server-side template injection (SSTI) mechanism used by the products. This vulnerability can be triggered by a malicious actor with network access, allowing them to inject arbitrary code into the template and execute it remotely.

If the vulnerability is successfully exploited, it can lead to severe consequences for an organization. Malicious actors can use the vulnerability to access sensitive data, steal credentials, and take control over accounts with elevated privileges. They can use the compromised accounts to install additional malware and ransomware on the affected systems, leading to data loss, theft, and system downtime. In short, the vulnerability can be used as a launchpad for advanced persistent threats, which can be difficult to detect and mitigate.

Thanks to the pro features of the s4e.io platform, readers of this article can take advantage of a comprehensive security assessment tool that can help them quickly identify vulnerabilities in their digital assets. The service provides a detailed report containing actionable insights into security gaps and recommendations for how to address them. By using the s4e.io platform, organizations can stay one step ahead of cyber threats and protect their assets effectively.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is necessary to follow a set of precautions:

  • Apply the latest security patches provided by VMware.
  • Monitor network traffic and look for signs of SSTI requests, which could be an indication of a possible vulnerability exploit attempt.
  • Restrict network access to critical systems and data, only allowing access to authorized users and devices.
  • Use a multi-layered security approach, including firewalls, intrusion detection and prevention systems, and endpoint protection.
  • Educate employees about the importance of cybersecurity and the risks of opening suspicious emails or clicking on links from unknown sources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-22954 scanner - Server Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access and Identity Manager | S4E