imPC@ndo IT

Tracker / CVE-2021-22056

CVE-2021-22056

High 7.5

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.

Affected products and versions

vmware identity_manager
vmware vrealize_automation
vmware vrealize_automation · 8.0 → 8.6
vmware workspace_one_access

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References