Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-31687

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
Attacker Value
Unknown

CVE-2022-31685

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
Attacker Value
Unknown

CVE-2022-31689

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
Attacker Value
Unknown

CVE-2022-31688

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
Attacker Value
Unknown

CVE-2022-31686

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.