Statement on CVE 2022-22960 VMware Vulnerability

Statement on CVE 2022-22960 VMware Vulnerability#

July 14, 2022

Information#

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to ‘root’.

Risk#

Low

Response#

Melissa Data Corporation (“Melissa”) was not impacted by the VMware vulnerabilities as Melissa does not utilize any of the impacted VMware products.

Melissa will continue to follow all guidance provided for this vulnerability as necessary to prevent any future risks.