---
# source: blog-content: posts/en/vmware-security-advisory-2022-021.md
# route:  /en/insights/vmware-security-advisory-2022-021/
title: VMware Security Advisory
date: 2022-08-05
author: dario-doerflinger
locale: en
summary: VMware has disclosed new vulnerabilities in VMware Security Advisory 2022-0021. They are rated 4.7 to 9.8 on the CVSS scale.
capabilities: [security]
vendors: [vmware]
hero: /blog-assets/vmware-security-advisory-2022-021/hero.webp
migrated: 2026-08-24
translationReviewed: false
draft: false
---

VMware has disclosed new vulnerabilities. They are covered by VMware Security Advisory 2022 0021 and rated 4.7 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be patched as soon as possible.

## VMSA-2022-021

The disclosed vulnerability ([CVE-2022-31656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31656)) lets an attacker with network access obtain administrator rights without logging in. Workspace ONE Access, Identity Manager and vRealize Automation are affected. Further detail, workarounds and patch links are at [VMware](https://www.vmware.com/security/advisories/VMSA-2022-0021.html).

VMware reports no known attacks so far. With a published vulnerability that can change within hours. Both soulTec and VMware recommend patching the affected systems immediately. If you need a hand, [we are here](https://soultec.ch/contact-us/).
