CVE-2022-22956
52Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 51%
from disclosure to weapon0 days
Published on NVDApr 13
metasploitApr 6
VulnCheck+1239d
exploitation probability
51%top 1% of all CVEs
observed exploitation
yesVulnCheck
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Affected products
n/a · VMware Workspace ONE Access