2022/05
VMSA-2022-0014: Workspace ONE Access and Identity Manager Critical Vulnerability
Reading time: 3 minutes
Hot on the heels of the recent April 2022 VMware critical security advisory VMSA-2022-0011, which addressed eight CVEs within VMware Workspace ONE Access and VMware Identity Manager, VMware has released a new creitical security advisory VMSA-2022-0014. This advisory addresses two new security vulnerabilities (CVE-2022-22972 and CVE-2022-22973) in VMware Workspace ONE Access and VMware Identity Manager, with one rated as critical.
Authentication Bypass Vulnerability - CVE-2022-22972 According to VMware, a malicious user with network access to the VMware Workspace ONE Access or VMware Identity Manager user interfaces may be able to obtain administrative access without needing to authenticate.
VMware vRealize Suite Lifecycle Manager 8.8.0 Locker Bug
Reading time: 4 minutes
One of my work colleagues brought to my attention today an issue in VMware vRealize Suite Lifecycle Manager 8.8.0 to my attention today. While attempting to complete some regular account password changes, he realized that the Password Locker was only returning 10 passwords and stating there were only 10 passwords in the system.
Introduction to vSphere Diagnostic Tool
Reading time: 3 minutes
While browsing the VMware Flings website, I recently ran across a Fling previously released in November of 2021 titled vSphere Diagnostic Tool that I found to be quite interesting. The tool is a set of python scripts that execute various diagnostic commands against a vCenter Server appliance. The scripts aim to rapidly isolate common known issues with vCenter Server appliances to aid and provide the end-user with information on how to remediate the problems.
VMware vRealize Operations 8.6.3 is Now Available
Reading time: 2 minutes
vRealize Operations has received its latest update on April 25, 2022. vRealize Operations 8.6.3 is a maintenance release which resolves several important security, performance, stability, and functionality issues identified in the product.
VMware vRealize Automation 8.8 Is Now Available
Reading time: 8 minutes
VMware has released the latest update to the vRealize Suite, vRealize Automation 8.8, on April 28, 2022. With this release, VMware has provided several enhancements and new features, including support for multi-level approval policies, enhanced custom naming for deployment resources, and support for legacy vRealize Orchestrator workflow presentations within vRealize Automation custom forms.