title: CVE-2022-31656 VMware Workspace ONE Access Auth Bypass id: fcf1101d-07c9-49b2-ad81-7e421ff96d80 status: test description: | Detects the exploitation of VMware Workspace ONE Access Authentication Bypass vulnerability as described in CVE-2022-31656 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. references: - https://petrusviet.medium.com/dancing-on-the-architecture-of-vmware-workspace-one-access-eng-ad592ae1b6dd author: Nasreddine Bencherchali (Nextron Systems) date: 2022-08-12 modified: 2023-01-02 tags: - attack.initial-access - attack.t1190 - cve.2022-31656 - detection.emerging-threats logsource: category: webserver detection: selection: cs-uri-query|contains: '/SAAS/t/_/;/' condition: selection falsepositives: - Vulnerability scanners level: high