CVE-2022-22954
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
Description
CVE-2022-22954 is a critical server-side template injection (SSTI) vulnerability in VMware Workspace ONE Access and VMware Identity Manager that enables unauthenticated remote code execution. The flaw allows an attacker to inject a specially crafted template into the server-side template engine, which is then evaluated and executed, granting the attacker full control over the underlying system. CISA has confirmed active exploitation and added CVE-2022-22954 to the Known Exploited Vulnerabilities catalog, and ransomware operators are known to exploit this flaw. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 97.4% (99.9th percentile), this vulnerability represents one of the most dangerous and actively targeted threats in enterprise identity management infrastructure.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| vmware | identity manager | 3.3.3; 3.3.4; 3.3.5; 3.3.6 |
| vmware | vrealize automation | 7.6 |
| vmware | workspace one access | 20.10.0.0; 20.10.0.1; 21.08.0.0; 21.08.0.1 |
| vmware | cloud foundation | >= 4.0, <= 4.3.1 |
| vmware | vrealize suite lifecycle manager | >= 8.0, <= 8.2 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injection-Command-Execution.html(Exploit, Third Party Advisory, VDB Entry)
- https://www.vmware.com/security/advisories/VMSA-2022-0011.html(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22954(US Government Resource)
Weakness Type
CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
CWE-1336 describes a weakness where software uses a template engine to process user-controllable input but fails to properly neutralize special elements or syntax that the engine interprets as executable instructions. In CVE-2022-22954, the VMware Workspace ONE Access and Identity Manager platform processes attacker-controlled input through a server-side template engine without proper sanitization, allowing injection of template directives that execute arbitrary code on the server.
Learn more: CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine
Impact Analysis
CVE-2022-22954 carries a CVSS score of 9.8 (CRITICAL) and is remotely exploitable without authentication or user interaction, making it trivially weaponizable against any exposed VMware Workspace ONE Access or Identity Manager instance. The confidentiality impact is devastating — attackers gain access to the identity provider's configuration, user credentials, SAML tokens, and OAuth secrets, enabling cascading compromise of all federated applications. The integrity impact is equally severe, as attackers can modify authentication policies, create backdoor accounts, or issue forged authentication tokens to access any connected system. Availability is fully compromised through ransomware deployment, which has been confirmed as a real-world exploitation pattern, or through destruction of the identity platform that all dependent applications rely upon.
Exploit Maturity
CVE-2022-22954 is actively exploited in the wild, listed in the CISA KEV catalog, and has confirmed usage by ransomware operators, making it one of the highest-risk vulnerabilities in the VMware ecosystem. The EPSS score of 97.4% (99.9th percentile) represents near-certain exploitation probability, reflecting widespread availability of public exploit code and active mass scanning campaigns. Multiple threat actors, including both opportunistic attackers and advanced persistent threat groups, have been documented exploiting this vulnerability within days of public disclosure. Proof-of-concept exploits are trivially accessible, and the attack requires only a single HTTP request to achieve code execution.
Remediation
- Apply VMware security patches immediately as required by CISA KEV: install the patches referenced in VMware Security Advisory VMSA-2022-0011 for Workspace ONE Access and Identity Manager.
- If immediate patching is not possible, apply the VMware-provided workaround to disable the vulnerable template processing endpoint.
- Monitor all Workspace ONE Access and Identity Manager instances for indicators of compromise, including unexpected administrative accounts, modified OAuth/SAML configurations, and anomalous outbound network connections.
- Audit authentication logs for evidence of token forgery, unauthorized access to federated applications, and suspicious login patterns that may indicate exploitation.
- After patching, rotate all SAML signing certificates, OAuth client secrets, and administrative credentials, as they may have been exfiltrated during any prior exploitation window.
Technical Details
CVE-2022-22954 is a server-side template injection vulnerability in VMware Workspace ONE Access and VMware Identity Manager, arising from improper handling of user-controllable input in the server-side template engine. The vulnerable endpoint processes HTTP request parameters through a template rendering pipeline without sanitizing template-specific syntax, allowing an attacker to inject template directives that are evaluated and executed by the server. The injected template code runs with the privileges of the VMware service process, enabling arbitrary command execution on the underlying operating system. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms the worst-case exploitation profile: network-accessible, low complexity, no privileges required, and no user interaction needed.
Frequently Asked Questions
Is CVE-2022-22954 being actively exploited?
Yes. CVE-2022-22954 is actively exploited in the wild and is listed in the CISA KEV catalog with confirmed ransomware usage. The EPSS score of 97.4% (99.9th percentile) reflects near-certain exploitation probability, and multiple threat actor groups have been observed targeting this vulnerability.
What products are affected by CVE-2022-22954?
CVE-2022-22954 affects VMware Workspace ONE Access (formerly VMware Identity Manager) and VMware Identity Manager. These products serve as identity providers and single sign-on platforms for enterprise applications.
How do I fix CVE-2022-22954?
Apply the security patches from VMware Security Advisory VMSA-2022-0011 immediately. If patching is delayed, implement VMware's recommended workaround. After patching, rotate all SAML certificates, OAuth secrets, and administrative credentials.
How severe is CVE-2022-22954?
CVE-2022-22954 is rated CRITICAL with a CVSS score of 9.8 and an EPSS score in the 99.9th percentile. Ransomware operators actively exploit this vulnerability. As an identity provider vulnerability, successful exploitation can cascade to compromise all federated applications and services.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.