CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

vmware

vrealize_automation

15 known vulnerabilities · sorted by CVSS score

CVE-2022-22972
CRITICAL9.8

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

vmware / identity_manager+59
Network
Published May 20, 2022
CVE-2022-22954
CRITICAL9.8

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

vmware / identity_manager+10
Network
Published Apr 11, 2022
CVE-2018-6959
CRITICAL9.8

VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.

vmware / vrealize_automation
Network
Published Apr 13, 2018
CVE-2022-22955
CRITICAL9.8

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

vmware / identity_manager+9
Network
Published Apr 13, 2022
CVE-2017-4947
CRITICAL9.8

VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.

vmware / vrealize_automation+2
Network
Published Jan 29, 2018
CVE-2022-22956
CRITICAL9.8

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

vmware / identity_manager+9
Network
Published Apr 13, 2022
CVE-2023-20855
HIGH8.8

VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.

vmware / vrealize_automation+1
Network
Published Feb 22, 2023
CVE-2022-22960
HIGH7.8

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

vmware / cloud_foundation+10
Local
Published Apr 13, 2022
CVE-2021-22056
HIGH7.5

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.

vmware / identity_manager+8
Network
Published Dec 20, 2021
CVE-2022-22958
HIGH7.2

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.

vmware / cloud_foundation+11
Network
Published Apr 13, 2022
CVE-2022-22957
HIGH7.2

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.

vmware / cloud_foundation+11
Network
Published Apr 13, 2022
CVE-2021-22036
MEDIUM6.5

VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator leading to sensitive information disclosure.

vmware / vrealize_automation+1
Network
Published Oct 13, 2021
CVE-2018-6958
MEDIUM6.1

VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation.

vmware / vrealize_automation
Network
Published Apr 13, 2018
CVE-2022-22961
MEDIUM5.3

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.

vmware / cloud_foundation+11
Network
Published Apr 13, 2022
CVE-2022-22959
MEDIUM4.3

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.

vmware / cloud_foundation+11
Network
Published Apr 13, 2022