.. / CVE-2022-22954

Exploit for VMware Workspace ONE Access - Server-Side Template Injection (CVE-2022-22954)

Description:

VMware Workspace ONE Access is susceptible to a remote code execution vulnerability due to a server-side template injection flaw. An unauthenticated attacker with network access could exploit this vulnerability by sending a specially crafted request to a vulnerable VMware Workspace ONE or Identity Manager.

Nuclei Template

View the template here CVE-2022-22954.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-22954.yaml
Copy

References:

https://www.tenable.com/blog/vmware-patches-multiple-vulnerabilities-in-workspace-one-vmsa-2022-0011
https://www.vmware.com/security/advisories/VMSA-2022-0011.html
http://packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injection-Command-Execution.html
https://nvd.nist.gov/vuln/detail/CVE-2022-22954