The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check whether you run VMware Workspace ONE Access (including its related identity/connector components) and whether the OAuth2 ACS/authentication endpoints are reachable from the network.
Compare your installed version to the vendor’s fixed release guidance; at minimum, ensure the impacted vrealize automation component is updated to a fixed level.
Upgrade to the fixed version(s) listed by VMware; for vrealize automation, apply the fix so it is “fixed in 9.0”.
If you cannot patch immediately, restrict network access so only trusted internal systems can reach the Workspace ONE Access OAuth2 authentication endpoints (block public reachability and limit inbound to required sources).
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
In plain language
Written by AI from the record
CVE-2022-22956 is an authentication-bypass flaw in VMware Workspace ONE Access—if your server’s OAuth2 authentication endpoints are reachable from the network, a remote attacker can log in without credentials and take over operations; this is a serious RED situation for affected businesses.
CVE-2022-22956 is an unauthenticated authentication-bypass in VMware Workspace ONE Access’s OAuth2 ACS framework via exposed authentication endpoints, allowing an attacker to bypass the authentication check and execute unauthorized operations.
If you're affected
Unauthorized admin/tenant actions
Full system takeover risk
Service disruption
Access control bypass
What is it
This vulnerability lets an attacker skip the “login” step that normally protects VMware Workspace ONE Access. Think of it like a building where the front door guard can be tricked into letting someone in without checking an ID. If the attacker can reach the exposed authentication endpoints, they may then perform actions as if they were trusted.
Who is affected
This matters if you run VMware Workspace ONE Access (including its Identity Manager / related workspace one access components and the Omnissa Workspace ONE Access Connector), because the flaw is in its OAuth2 authentication (ACS) framework. This is a remote, network-based risk and the findings indicate no authentication is required to trigger the bypass.
The risk is highest when the exposed authentication endpoints are reachable from the network (reachability details weren’t confirmed as “default enabled” in the findings, so you should verify your specific exposure).
How urgent is it
RED: the findings indicate an attacker can bypass authentication over the network with no authentication required, and public exploit tooling is available. Treat this as an actively exploitable, high-impact auth bypass and prioritize patching and network containment immediately for any reachable installations.
What to do — in detail
Confirm exposure (what to check)
Identify where VMware Workspace ONE Access is deployed (including the related identity manager/workspace one access components and the Omnissa Workspace ONE Access Connector).
Determine how inbound traffic is routed to these systems, and specifically whether the OAuth2 ACS/authentication endpoints are reachable from outside your trusted network.
Check firewall rules, reverse proxy/WAF rules, load balancer listeners, and any public DNS/ingress pointing to Workspace ONE Access.
If you have logs, search for inbound requests to authentication/OAuth-related paths at times that match your user/admin access patterns.
Verify your current software versions against VMware’s advisory VMSA-2022-0011 guidance (the findings include at least one concrete fixed point for vrealize automation).
Patch/upgrade
Patch using VMware’s remediation guidance.
For vrealize automation, the findings state the issue is “fixed in 9.0”. Upgrade that component to the fixed state per VMware’s instructions.
For VMware Workspace ONE Access and related components (identity manager / workspace one access / Omnissa Workspace ONE Access Connector), use the same VMware advisory to identify the exact fixed versions for your branch—those fixed-version details are not fully enumerated in the findings provided.
If patching is delayed (temporary workaround)
Block public reachability to the Workspace ONE Access OAuth2 authentication endpoints.
Restrict inbound access to only the specific internal systems that must reach it (tight IP allowlists / network segments), and ensure any reverse proxy/WAF is not exposing those endpoints to the internet.
Monitor after changes
Monitor inbound request logs for OAuth/authentication endpoint probing.
Monitor Workspace ONE Access administrative/audit logs for unusual operations that could indicate attempted bypass activity.
Timeline
Apply containment first if endpoints are reachable; then complete the upgrade to the fixed version guidance as soon as possible.
(KEV/CISA listing was not provided in the findings, so there is no due date from KEV here.)
Technical context
What’s vulnerable
CVE-2022-22956 is an authentication bypass (CWE-287) in VMware Workspace ONE Access’s OAuth2 ACS framework. The findings state that an attacker can bypass authentication and execute unauthorized operations.
Attack characteristics
Network-based attack vector.
No authentication required to trigger the bypass (per findings).
No user interaction required (per findings).
Public exploit tooling exists (2 known).
Exploitation status
The findings do not list this CVE in CISA KEV, but they do state that public exploits are available. Given the RED verdict and the exploit availability, treat this as a high-risk, actively actionable flaw.
Fix guidance
The findings include a concrete remediation point for vrealize automation: fixed in 9.0. VMware’s advisory VMSA-2022-0011 contains the authoritative remediation instructions for the affected Workspace ONE Access ecosystem components, including any fixed versions for your specific deployment.
EPSS
EPSS data was provided as a prediction, but the findings do not include KEV/news confirmation of widespread exploitation; this section is not used to drive the decision because exploit availability and the RED verdict are decisive.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.