Skip to main content

CVE detail

CVE-2022-22954

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CVSS 9.8 · CriticalBuzz score 78.5KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 78.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 7.5
Mention score
30.0
30 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
7.5
1 repos · best confidence 0.99
Best PoC traction
1253
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
30 source links · newest first
  • Executive Summary Research by Erez Goldberg Server-Side Template Injection (SSTI) vulnerabilities refer to weaknesses in web applications which attackers can exploit to inject malicious code into server-side templates. This allows them to execute arbitrary commands on the server, potentially leading to unauthorized data access, server compromise, or exploitation of additional vulnerabilities. Recently, SSTI vulnerabilities are […]

    vendorresearch.checkpoint.comAug 14, 2024, 1:00 PM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.

    newswww.securityweek.comAug 4, 2023, 9:08 AM
  • CISA, the FBI, and NSA, along with Five Eyes cybersecurity agencies published a list of the 12 most exploited vulnerabilities of 2022. CISA, the NSA, and the FBI, in collaboration with cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom, have published a list of the 12 most exploited vulnerabilities of 2022. The […]

    newssecurityaffairs.comAug 4, 2023, 6:30 AM
  • The number of fileless or memory-based attacks that exploit existing software, applications, and protocols have surged 1,400% in the last year. That’s according to Aqua Security’s 2023 Cloud Native Threat Report, which summarizes research and observations of threat actors’ changing tactics, techniques, and procedures (TTPs), along with outlining strategies for protecting cloud environments. Based on […]

    newswww.csoonline.comJun 27, 2023, 8:00 AM
  • A new research report discusses the five most exploited vulnerabilities of 2022, and the five key risks that security teams should consider.

    newswww.securityweek.comMar 29, 2023, 11:45 AM
  • 24th October – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 24th October, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Iranian Hacktivist group ‘Black Reward’ claim to have breached Iran’s government and exfiltrated data related to the country’s nuclear program. After the group’s demands to release political prisoners were not met, the group […]

    vendorresearch.checkpoint.comOct 24, 2022, 9:33 AM
  • Threat actors are exploiting a now-patched vulnerability, tracked as CVE-2022-22954, in VMware Workspace ONE Access in attacks in the wild. Threat actors are actively exploiting a now-patched vulnerability, tracked as CVE-2022-22954, in VMware Workspace ONE Access to deliver cryptocurrency miners and ransomware. The issue causes server-side template injection due to because of the lack of […]

    newssecurityaffairs.comOct 22, 2022, 3:31 PM
  • Recent exploits observed in the wild are highlighted based on the availability of proofs of concept, the severity of the vulnerabilities the exploits are based on and the ease of exploitation.

    vendorunit42.paloaltonetworks.comAug 19, 2022, 11:00 PM
  • The U.S. CISA and the Coast Guard Cyber Command (CGCYBER) warn of attacks exploiting the Log4Shell flaw in VMware Horizon servers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with the Coast Guard Cyber Command (CGCYBER), published a joint advisory to warn of hacking attempts exploiting the Log4Shell flaw in VMware Horizon servers to […]

    newssecurityaffairs.comJun 24, 2022, 3:07 PM
  • If your organization is running VMware Horizon and Unified Access Gateway servers and you haven’t implemented the patches or workarounds to fix/mitigate the Log4Shell vulnerability (CVE-2021-44228) in December 2021, you should threat all those systems as compromised, the Cybersecurity and Infrastructure Security Agency (CISA) has advised on Thursday. The agency accompanied the warning with detailed technical information and indicators of compromised related to two separate incident response engagements they and the United States Coast Guard … More →

    newswww.helpnetsecurity.comJun 24, 2022, 9:41 AM
  • Metasploit is the world’s most used penetration testing framework. It helps security teams verify vulnerabilities, manage security assessments, and improve security awareness. Metasploit 6.2.0 is now available. It includes 138 new modules, 148 enhancements and features, improvements, and 156 bug fixes. “Our continued focus for Metasploit is on on adding support for modern attacks so the community can highlight risk and test security controls for paths that attackers use regularly. Metasploit 6.2.0 continued this theme … More →

    newswww.helpnetsecurity.comJun 13, 2022, 12:14 PM
  • The operators of the EnemyBot botnet added exploits for recently disclosed flaws in VMware, F5 BIG-IP, and Android systems. Operators behind the EnemyBot botnet are expanding the list of potential targets adding exploits for recently disclosed critical vulnerabilities in from VMware, F5 BIG-IP, and Android. The botnet was first discovered by Fortinet in March, the […]

    newssecurityaffairs.comMay 30, 2022, 7:09 AM
  • When VMware announced patches for a critical vulnerability on May 18, users were warned that exploitation in the wild would likely start soon, and now a proof-of-concept (PoC) exploit targeting the flaw has been made public.

    newswww.securityweek.comMay 27, 2022, 6:15 PM
  • CVE-2022-22954, one of several recently published VMware vulnerabilities, is being exploited in the wild. Read our observations and recommendations.

    vendorunit42.paloaltonetworks.comMay 20, 2022, 1:00 PM
  • The U.S. Cybersecurity and Infrastructure Agency (CISA) has issued an emergency directive over two new vulnerabilities in VMware products. According to the advisory, threat actors are likely to exploit CVE-2022-22972 and CVE-2022-22973 in several products including VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite […]

    newswww.csoonline.comMay 19, 2022, 1:10 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations about two actively exploited VMware product vulnerabilities, and the agency believes two other freshly patched flaws will also be exploited soon.

    newswww.securityweek.comMay 19, 2022, 9:57 AM
  • VMware has released patches for a privately reported critical vulnerability (CVE-2022-22972) in VMware’s Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products, and is urging administrators to patch or mitigate immediately, because “the ramifications of this vulnerability are serious.” Simultaneously, the Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive for all federal civilian executive branch agencies, which are ordered to enumerate all instances of … More →

    newswww.helpnetsecurity.comMay 19, 2022, 9:25 AM
  • CISA orders federal agencies to fix VMware CVE-2022-22972 and CVE-2022-22973 vulnerabilities by May 23, 2022. The Cybersecurity and Infrastructure Security Agency (CISA) issued the Emergency Directive 22-03 to order federal agencies to fix VMware CVE-2022-22972 and CVE-2022-22973 flaws or to remove the affected products from their networks by May 23, 2022. The list of impacted […]

    newssecurityaffairs.comMay 19, 2022, 6:13 AM
  • 2nd May – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 2nd May, please download our Threat Intelligence Bulletin. Top Attacks and Breaches North Korean government connected group initiated in March 2022 a spear-phishing campaign against journalists who specialize in the North Korea coverage. The group used Goldbackdoor malware that is linked to malware families […]

    vendorresearch.checkpoint.comMay 2, 2022, 2:43 PM
  • The Iran-linked APT group Rocket Kitten has been observed exploiting a recently patched CVE-2022-22954 VMware flaw. Iran-linked Rocket Kitten APT group has been observed exploiting a recently patched CVE-2022-22954 VMware Workspace ONE Access flaw to deploy ‘Core Impact’ Backdoor. The CVE-2022-22954 vulnerability is a server-side template injection remote code execution issue, it was rated 9.8 […]

    newssecurityaffairs.comApr 26, 2022, 6:00 PM
  • 18th April – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 18th April, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Russian state-sponsored APT actor Sandworm made an attempt to hack into Ukraine’s power grid with the Industroyer2 malware, aiming at taking down multiple infrastructure components. The malware forensic analysis has revealed that […]

    vendorresearch.checkpoint.comApr 18, 2022, 10:48 AM
  • A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. U.S. Gov believes North Korea-linked Lazarus APT is behind Ronin Validator cyber heist The […]

    newssecurityaffairs.comApr 17, 2022, 9:53 AM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Microsoft fixes actively exploited zero-day reported by the NSA (CVE-2022-24521) On this April 2022 Patch Tuesday, Microsoft has released patches for 128 CVE-numbered vulnerabilities, including one zero-day exploited in the wild (CVE-2022-24521) and another (CVE-2022-26904) for which there’s already a PoC and a Metasploit module. Critical Microsoft RPC runtime bug: No PoC exploit yet, but patch ASAP! (CVE-2022-26809) Since Microsoft’s latest … More →

    newswww.helpnetsecurity.comApr 17, 2022, 8:00 AM
  • Cloud computing and virtualization technology firm VMWare on Thursday rolled out patches for an extremely critical security flaw in the VMWare Cloud Director product, warning that unpatched systems are at risk of remote code execution attacks.

    newswww.securityweek.comApr 14, 2022, 6:42 PM
  • Threat actors are actively exploiting a critical vulnerability in VMware Workspace ONE Access and Identity Manager recently patched by the vendor. Threat actors are actively exploiting a critical flaw, tracked as CVE-2022-22954, in VMware Workspace ONE Access and Identity Manager recently patched by the vendor. Researchers from cyber threat intelligence BadPackets also reported that the vulnerability […]

    newssecurityaffairs.comApr 14, 2022, 10:42 AM
  • Cyber crooks have begun exploiting CVE-2022-22954, a RCE vulnerability in VMware Workspace ONE Access and Identity Manager, to deliver cryptominers onto vulnerable systems. About CVE-2022-22954 CVE-2022-22954 is, in effect, a server-side template injection vulnerability that can be triggered by a malicious actor with network access to achieve remote code execution. It was reported to VMware privately and a fix and a workaround for it was released on April 6, along with fixes for seven other … More →

    newswww.helpnetsecurity.comApr 14, 2022, 8:39 AM
  • Less than a week after patching critical security defects affecting multiple enterprise-facing products, VMware is warning that one of the flaws is being exploited in the wild.

    newswww.securityweek.comApr 13, 2022, 10:36 PM
  • VMware on Wednesday announced patches for several critical and high-severity vulnerabilities affecting Workspace ONE Access and other products.

    newswww.securityweek.comApr 7, 2022, 10:09 AM
  • VMware fixed critical vulnerabilities in multiple products that could be exploited by remote attackers to execute arbitrary code. VMware has addressed critical remote code vulnerabilities in multiple products, including VMware’s Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products. The virtualization giant urges its customers to address […]

    newssecurityaffairs.comApr 7, 2022, 7:10 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 1253 stars
  • W01fh4cker/SereinHigh confidence
    githubDiscovery source unavailable1253 starsDiscovered Jul 9, 2026, 1:19 AM

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence