VMware Releases Security Update for Workspace ONE UEM console
Security update to address a Server Side Request Forgery vulnerability in VMware Workspace ONE UEM console
Summary
Security update to address a Server Side Request Forgery vulnerability in VMware Workspace ONE UEM console
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released a security advisory to address a Server Side Request Forgery (SSRF) vulnerability, tracked as CVE-2021-22054, in Workspace ONE UEM console. VMware has rated the severity of this issue as 'critical'.
An attacker with network access to UEM could send requests without authentication and may exploit this issue to gain access to sensitive information.
Remediation advice
Affected organisations are encouraged to review VMware Security Advisory VMSA-2021-0029 and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 30 December 2021 3:11 pm