S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-22972 Scanner

CVE-2022-22972 scanner - Authentication Bypass vulnerability in VMware Workspace ONE Access, Identity Manager and vRealize Automation

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-22972
9.8
CVSS

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
VMware Workspace ONE Access, Identity Manager and vRealize Automationby n/a
Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0. Identity Manager 3.3.6, 3.3.5, 3.3.4, 3.3.3. vRealize Automation 7.6.
Updated Aug 22, 2026View on NVD →
Detail

VMware Workspace ONE Access, Identity Manager, and vRealize Automation are powerful tools used by organizations to centralize and streamline access to their digital assets. These products enable IT administrators to manage user identities and permissions across a wide range of applications and services, ensuring that access is only granted to authorized users.

However, these products are not without their vulnerabilities. One such vulnerability, identified as CVE-2022-22972, allows for an authentication bypass. This means that a malicious actor who has network access to the user interface may be able to gain administrative access without the need to authenticate. This is a serious security flaw that can potentially put an organization's sensitive data at risk.

When exploited, this vulnerability can lead to a number of serious consequences. A hacker who gains administrative access can potentially access and manipulate sensitive data, steal personal information, and wreak havoc on an organization's systems. This can result in financial loss, damage to reputation, and a loss of trust among customers and stakeholders.

With the pro features of the s4e.io platform, organizations can easily and quickly learn about vulnerabilities in their digital assets. This platform provides actionable insights and recommendations to help organizations stay ahead of potential threats and protect their sensitive data. Don't wait until it's too late - take action now to safeguard your organization's critical assets.

 

REFERENCES

Solution Advice

Thankfully, there are precautions that organizations can take to protect against this vulnerability. Some examples include:

  • Implementing multi-factor authentication to add an extra layer of security
  • Ensuring that all software and security updates are installed promptly
  • Monitoring network activity for any suspicious behavior
  • Limiting access to critical systems and data to only authorized personnel

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.