LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22954: VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 14, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22954 to its Known Exploited Vulnerabilities catalog on Apr 14, 2022, with a federal patch deadline of May 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

CVE-2022-22954 is a server-side template injection flaw in VMware Workspace ONE Access and Identity Manager that can allow remote code execution. CISA notes that this vulnerability has been used by ransomware operators, so organizations running these identity products should treat it as a high-priority risk to authentication and access infrastructure.

Because these components often sit at the front of enterprise single sign-on and identity workflows, successful exploitation can give an attacker a foothold with broad reach. Confirm exact affected builds and fixed releases against the vendor advisory before acting.

How it works

The weakness is classified as CWE-94 (improper control of code generation). In products that render server-side templates, user-controlled input is sometimes passed into a template engine without adequate sanitization or sandboxing. An attacker who can supply crafted template expressions may cause the engine to evaluate them on the server, leading to arbitrary code execution in the context of the application process.

For VMware Workspace ONE Access and Identity Manager, CISA summarizes the issue simply: the products allow remote code execution due to server-side template injection. Public detail beyond that class of abuse is limited here; do not assume specific request parameters, endpoints, or payloads. Treat any unauthenticated or low-privilege ability to influence template rendering as the core risk and verify exploitation prerequisites only from the vendor advisory and your own testing in a lab.

Am I affected? How to find it in your systems

Workspace ONE Access and Identity Manager are typically deployed as appliances or services that provide identity federation, catalog access, and authentication for VMware and third-party applications. They often run in DMZs or identity zones and may be reachable from the internet or broad internal networks.

If you cannot determine the exact build, assume potential exposure until you verify otherwise.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed packages or appliance updates named in VMware’s advisory for Workspace ONE Access and Identity Manager, stage them in a test environment, then deploy to production with normal change control.

Do not rely on workarounds as a substitute for the vendor fix when the patch is available.

If you can't patch immediately

Reduce exposure until you can update:

These steps only buy time; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities of this class, especially those with known ransomware use, frequently precede broader compromise of identity systems and downstream applications. If you find evidence of exploitation or cannot rule it out, follow your incident response plan: isolate affected hosts, preserve logs and memory where feasible, reset privileged credentials, and assess lateral movement.

You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public compilations, then force password resets and enable stronger MFA where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · Workspace ONE Access and Identity Manager
WeaknessCWE-94
Added to CISA KEVApr 14, 2022
Federal patch deadlineMay 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities