HTTP: VMWare Workspace One UEM Server Side Request Forgery

This signature detects attempts to exploit a known vulnerability against VMware Workspace ONE UEM console. A successful attack can lead to sensitive information disclosure.

Extended Description

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

Affected Products

Vmware workspace_one_uem_console

References

CVE: CVE-2021-22054

Short Name
HTTP:CTS:VMWARE-ONE-UEM-SSRF
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2021-22054 Forgery One Request Server Side UEM VMWare Workspace
Release Date
11/23/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3548
False Positive
Unknown
Vendors

Vmware

Found a potential security threat?