漏洞描述 VMware Workspace ONE Access(以前称为VMware IdentityManager)旨在通过多因素身份验证、条件访问和单点登录,让您的员工更快地访问SaaS、Web和本机移动应用程序。该程序未经身份验证的攻击者可以利用此漏洞进行远程任意代码执行。ip靶机没有回显,去解析一个自己的域名上去就可以利用.
相关漏洞推荐 POC CVE-2018-6961: VMware NSX SD-WAN Edge - Command Injection POC CVE-2021-20617: Acmailer - Improper Access Control to OS Command Injection POC CVE-2022-4940: WCFM Membership <= 2.10.0 - Broken Access Control POC CVE-2025-63387: Dify v1.9.1 - Broken Access Control POC jboss-jmx-console-unauth: JBoss JMX Console - Unauthenticated Access POC nexus-repository-anonymous-access: Nexus Repository Manager - Anonymous Access Enabled POC CVE-2019-25213: WordPress Advanced Access Manager - Path Traversal POC CVE-2023-3277: MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation POC CVE-2024-47308: Templately <= 3.1.2 - Broken Access Control POC CVE-2025-64525: Astro - Broken Access Control POC unauth-akhq-dashboard: AKHQ Dashboard - Unauthenticated Access POC unauth-kafka-config-editor: Kafka Config Editor - Unauthenticated Access POC unauth-qdrantui: Qdrant UI - Unauthenticated Access