.. / CVE-2022-31656

Exploit for VMware - Local File Inclusion (CVE-2022-31656)

Description:

VMware Workspace ONE Access, Identity Manager, and Realize Automation are vulnerable to local file inclusion because they contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Nuclei Template

View the template here CVE-2022-31656.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-31656.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-31656
https://github.com/ARPSyndicate/cvemon
https://www.vmware.com/security/advisories/VMSA-2022-0021.html
https://github.com/ARPSyndicate/kenzer-templates
https://petrusviet.medium.com/dancing-on-the-architecture-of-vmware-workspace-one-access-eng-ad592ae1b6dd