Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown
CVE-2022-22944
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary script within a user's window.
0
Attacker Value
Unknown
CVE-2021-22056
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.
0
Attacker Value
Unknown
CVE-2021-22057
Disclosure Date: December 20, 2021 (last updated November 28, 2024)
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.
0
Attacker Value
Unknown
CVE-2021-22054
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
0
Attacker Value
Unknown
CVE-2021-22002
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.
0
Attacker Value
Unknown
CVE-2021-22003
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.
0
Attacker Value
Unknown
CVE-2021-22029
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate limiting.
0
Attacker Value
Unknown
CVE-2021-21990
Disclosure Date: May 11, 2021 (last updated February 22, 2025)
VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 2003 prior to 20.3.0.23, 2001 prior to 20.1.0.32, 1912 prior to 19.12.0.24) contain a cross-site scripting vulnerability. VMware Workspace ONE UEM console does not validate incoming requests during device enrollment after leading to rendering of unsanitized input on the user device in response.
0
Attacker Value
Unknown
CVE-2020-3940
Disclosure Date: January 17, 2020 (last updated February 21, 2025)
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2018-6976
Disclosure Date: September 11, 2018 (last updated November 27, 2024)
The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted filenames and associated metadata in SQLite database for the Content Locker.
0