Show filters
126 Total Results
Displaying 51-60 of 126
Sort by:
Attacker Value
Unknown
CVE-2022-22973
Disclosure Date: May 20, 2022 (last updated October 07, 2023)
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
0
Attacker Value
Unknown
CVE-2022-25865
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.
0
Attacker Value
Unknown
CVE-2021-39040
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025.
0
Attacker Value
Unknown
CVE-2022-22392
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.
0
Attacker Value
Unknown
CVE-2022-22944
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary script within a user's window.
0
Attacker Value
Unknown
CVE-2022-21825
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
0
Attacker Value
Unknown
CVE-2022-21823
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
0
Attacker Value
Unknown
CVE-2021-22056
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.
0
Attacker Value
Unknown
CVE-2021-22057
Disclosure Date: December 20, 2021 (last updated November 28, 2024)
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.
0
Attacker Value
Unknown
CVE-2021-22054
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
0