iTnews
  • Home
  • News
  • Technology
  • Security

VMware admins asked to patch eight vulnerabilities

By Richard Chirgwin on Apr 7, 2022 4:40PM
VMware admins asked to patch eight vulnerabilities

Authentication bypass, remote code execution, and more.

VMware has patched eight bugs in five of its products that were uncovered by Qihoo 360 security researcher Steven Seeley.

An advisory notes the eight vulnerabilities affect five different products: Workspace ONE Access, Identity Manager, vRealize Automation, Cloud Foundation, and vRealize Suite Lifecycle Manager.

Workspace ONE Access is impacted by two critical authentication bypass vulnerabilities, denoted as CVE-2022-22955 and CVE-2022-22956. 

They would allow an attacker to “bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework”, the advisory says.

Workspace ONE Access is also affected by a critical remote code execution vulnerability, CVE-2022-22954.

The vulnerability arises because of server-side template injection, the advisory stated. 

If a malicious attacker triggers the template injection, they can gain remote code execution.

The next pair of critical remote code execution vulnerabilities, CVE-2022-22957 and CVE-2022-22958, affect several products: VMware Workspace ONE Access, Identity Manager and vRealize Automation.

“A malicious actor with administrative access can trigger deserialisation of untrusted data through malicious JDBC (Java database connectivity) URI which may result in remote code execution," the advisory states.

The same three products also suffer a less-severe cross-site request forgery bug, CVE-2022-22959, in which a user could be tricked into validating a malicious JDBC URI.

The final two less-severe bugs are CVE-2022-22960, a local privilege escalation bug; and CVE-2022-22961, an information disclosure vulnerability.

Patches and workarounds are available for all bugs.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
patchsecurityvmwarevulnerabilities

Partner Content

Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats
Why Genworth Australia embraced low-code software development
Promoted Content Why Genworth Australia embraced low-code software development

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Richard Chirgwin
Apr 7 2022
4:40PM
0 Comments

Related Articles

  • Patches out for serious vulnerabilities in several VMware products
  • Atlassian discloses critical bugs
  • Juniper Networks battles swarm of bugs
  • Cisco collaboration software vulnerabilities fixed
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Australian court finds insurer not liable for ransomware clean-up costs

Australian court finds insurer not liable for ransomware clean-up costs

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

ADHA extends Accenture's My Health Record support deal for $100m

ADHA extends Accenture's My Health Record support deal for $100m

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

Digital Nation

COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
Domino’s invests in observability for zero contact delivery
Domino’s invests in observability for zero contact delivery
Metaverses on the agenda for Dominello, Husic ministerial meeting
Metaverses on the agenda for Dominello, Husic ministerial meeting
Criteo to fork out $94.7m for consent breaches
Criteo to fork out $94.7m for consent breaches
Australia will lose 11 percent of jobs to automation by 2040: Forrester
Australia will lose 11 percent of jobs to automation by 2040: Forrester
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.