Show filters
126 Total Results
Displaying 31-40 of 126
Sort by:
Attacker Value
Unknown

CVE-2023-34064

Disclosure Date: December 12, 2023 (last updated December 19, 2023)
Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.
Attacker Value
Unknown

CVE-2023-6588

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.
Attacker Value
Unknown

CVE-2023-20886

Disclosure Date: October 31, 2023 (last updated November 09, 2023)
VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user.
Attacker Value
Unknown

CVE-2023-22060

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Vulnerability in the Oracle Hyperion Workspace product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Workspace accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Workspace accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Workspace. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L).
Attacker Value
Unknown

CVE-2023-24486

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.
Attacker Value
Unknown

CVE-2023-30955

Disclosure Date: June 29, 2023 (last updated October 08, 2023)
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with workspace-server 7.7.0.
Attacker Value
Unknown

CVE-2023-20884

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
Attacker Value
Unknown

CVE-2023-2257

Disclosure Date: April 24, 2023 (last updated October 08, 2023)
Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This vulnerability occurs only if "Force Login" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business space.
Attacker Value
Unknown

CVE-2023-20857

Disclosure Date: February 28, 2023 (last updated October 08, 2023)
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.
Attacker Value
Unknown

CVE-2023-24484

Disclosure Date: February 15, 2023 (last updated October 08, 2023)
A malicious user can cause log files to be written to a directory that they do not have permission to write to.