A Vulnerability in VMware Products Could Allow for Authentication Bypass

Multiple vulnerabilities have been discovered in VMware Products, the most severe of which could result in Authentication Bypass.

  • VMware Workspace ONE Access is an access control application for Workspace ONE.
  • VMware Identity Manager is the identity and access management component of Workspace ONE.
  • vRealize Automationi is a management platform for automating the delivery of container-based applications.
  • VMware Cloud Foundation is a hybrid cloud platform that provides a set of software-defined services for compute, storage, networking, security and cloud management to run enterprise apps.
  • vRealize Suite Lifecycle Manager allows for complete lifecycle and content management capabilities for vRealize Suite products.
    Successful exploitation of the most severe of these vulnerabilities could result in Authentication Bypass. A malicious actor may be able to obtain administrative access. Depending on the permission associated with the application running the exploit, an attacker could then install programs; view, change, or delete data.

Read more... Cyber Security Advisories - MS-ISAC