CVE-2022-22954

CRITICAL(9.8)KEVRansomwareLikely Exploited

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

Description

CVE-2022-22954 is a critical server-side template injection (SSTI) vulnerability in VMware Workspace ONE Access and VMware Identity Manager that enables unauthenticated remote code execution. The flaw allows an attacker to inject a specially crafted template into the server-side template engine, which is then evaluated and executed, granting the attacker full control over the underlying system. CISA has confirmed active exploitation and added CVE-2022-22954 to the Known Exploited Vulnerabilities catalog, and ransomware operators are known to exploit this flaw. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 97.4% (99.9th percentile), this vulnerability represents one of the most dangerous and actively targeted threats in enterprise identity management infrastructure.

KEV Information

Vendor
VMware
Product
Workspace ONE Access and Identity Manager
Date Added
April 14, 2022
Due Date
May 5, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
vmwareidentity manager3.3.3; 3.3.4; 3.3.5; 3.3.6
vmwarevrealize automation7.6
vmwareworkspace one access20.10.0.0; 20.10.0.1; 21.08.0.0; 21.08.0.1
vmwarecloud foundation>= 4.0, <= 4.3.1
vmwarevrealize suite lifecycle manager>= 8.0, <= 8.2

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine

CWE-1336 describes a weakness where software uses a template engine to process user-controllable input but fails to properly neutralize special elements or syntax that the engine interprets as executable instructions. In CVE-2022-22954, the VMware Workspace ONE Access and Identity Manager platform processes attacker-controlled input through a server-side template engine without proper sanitization, allowing injection of template directives that execute arbitrary code on the server.

Learn more: CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine

Impact Analysis

CVE-2022-22954 carries a CVSS score of 9.8 (CRITICAL) and is remotely exploitable without authentication or user interaction, making it trivially weaponizable against any exposed VMware Workspace ONE Access or Identity Manager instance. The confidentiality impact is devastating — attackers gain access to the identity provider's configuration, user credentials, SAML tokens, and OAuth secrets, enabling cascading compromise of all federated applications. The integrity impact is equally severe, as attackers can modify authentication policies, create backdoor accounts, or issue forged authentication tokens to access any connected system. Availability is fully compromised through ransomware deployment, which has been confirmed as a real-world exploitation pattern, or through destruction of the identity platform that all dependent applications rely upon.

Exploit Maturity

CVE-2022-22954 is actively exploited in the wild, listed in the CISA KEV catalog, and has confirmed usage by ransomware operators, making it one of the highest-risk vulnerabilities in the VMware ecosystem. The EPSS score of 97.4% (99.9th percentile) represents near-certain exploitation probability, reflecting widespread availability of public exploit code and active mass scanning campaigns. Multiple threat actors, including both opportunistic attackers and advanced persistent threat groups, have been documented exploiting this vulnerability within days of public disclosure. Proof-of-concept exploits are trivially accessible, and the attack requires only a single HTTP request to achieve code execution.

Remediation

  1. Apply VMware security patches immediately as required by CISA KEV: install the patches referenced in VMware Security Advisory VMSA-2022-0011 for Workspace ONE Access and Identity Manager.
  2. If immediate patching is not possible, apply the VMware-provided workaround to disable the vulnerable template processing endpoint.
  3. Monitor all Workspace ONE Access and Identity Manager instances for indicators of compromise, including unexpected administrative accounts, modified OAuth/SAML configurations, and anomalous outbound network connections.
  4. Audit authentication logs for evidence of token forgery, unauthorized access to federated applications, and suspicious login patterns that may indicate exploitation.
  5. After patching, rotate all SAML signing certificates, OAuth client secrets, and administrative credentials, as they may have been exfiltrated during any prior exploitation window.

Technical Details

CVE-2022-22954 is a server-side template injection vulnerability in VMware Workspace ONE Access and VMware Identity Manager, arising from improper handling of user-controllable input in the server-side template engine. The vulnerable endpoint processes HTTP request parameters through a template rendering pipeline without sanitizing template-specific syntax, allowing an attacker to inject template directives that are evaluated and executed by the server. The injected template code runs with the privileges of the VMware service process, enabling arbitrary command execution on the underlying operating system. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms the worst-case exploitation profile: network-accessible, low complexity, no privileges required, and no user interaction needed.

Frequently Asked Questions

Is CVE-2022-22954 being actively exploited?

Yes. CVE-2022-22954 is actively exploited in the wild and is listed in the CISA KEV catalog with confirmed ransomware usage. The EPSS score of 97.4% (99.9th percentile) reflects near-certain exploitation probability, and multiple threat actor groups have been observed targeting this vulnerability.

What products are affected by CVE-2022-22954?

CVE-2022-22954 affects VMware Workspace ONE Access (formerly VMware Identity Manager) and VMware Identity Manager. These products serve as identity providers and single sign-on platforms for enterprise applications.

How do I fix CVE-2022-22954?

Apply the security patches from VMware Security Advisory VMSA-2022-0011 immediately. If patching is delayed, implement VMware's recommended workaround. After patching, rotate all SAML certificates, OAuth secrets, and administrative credentials.

How severe is CVE-2022-22954?

CVE-2022-22954 is rated CRITICAL with a CVSS score of 9.8 and an EPSS score in the 99.9th percentile. Ransomware operators actively exploit this vulnerability. As an identity provider vulnerability, successful exploitation can cascade to compromise all federated applications and services.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score100.00%
EPSS Percentile100.0%

Dates

PublishedApril 11, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.