Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown

CVE-2023-34064

Disclosure Date: December 12, 2023 (last updated December 19, 2023)
Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.
Attacker Value
Unknown

CVE-2023-20886

Disclosure Date: October 31, 2023 (last updated November 09, 2023)
VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user.
Attacker Value
Unknown

CVE-2023-20884

Disclosure Date: May 30, 2023 (last updated February 25, 2025)
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
Attacker Value
Unknown

CVE-2023-20857

Disclosure Date: February 28, 2023 (last updated February 24, 2025)
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.
Attacker Value
Unknown

CVE-2022-31687

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
Attacker Value
Unknown

CVE-2022-31685

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
Attacker Value
Unknown

CVE-2022-31689

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
Attacker Value
Unknown

CVE-2022-31686

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
Attacker Value
Unknown

CVE-2022-31688

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
Attacker Value
Unknown

CVE-2022-22973

Disclosure Date: May 20, 2022 (last updated October 07, 2023)
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.