VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
2023-05-30T16:15:09.390
2025-01-10T19:15:31.997
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | identity_manager | 3.3.6 | Yes |
Application | vmware | identity_manager | 3.3.7 | Yes |
Operating System | linux | linux_kernel | - | No |
Application | vmware | workspace_one_access | ≤ 22.09.1.0 | Yes |
Operating System | linux | linux_kernel | - | No |
Application | vmware | cloud_foundation | - | Yes |
Application | vmware | identity_manager_connector | * | Yes |
Operating System | microsoft | windows | - | No |