VMware Security Update – 01 November 2023

VMware has released a security update to address a vulnerability affecting several versions of VMware Workspace ONE UEM.

The addressed vulnerability could allow the remote attacker to conduct phishing attacks by redirecting the victim to arbitrary websites to retrieve the SAML response to login as the victim user.

VMware Workspace ONE UEM Open Redirect Vulnerability (CVE-2023-20886):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Obtain Information

Affected versions:

  • VMware Workspace ONE UEM versions 22.12.x, 22.9.x, 22.6.x, 22.3.x.
  • VMware Workspace ONE UEM version 23.6.x, 23.2.x.
Vulnerabilities

CVE-2023-20886

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References