CVE-2020-3940: VMware Workspace One Boxer

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.

Affected products

  • VMware Workspace One Boxer: before 5.13.1 (fixed in 5.13.1)
  • VMware Workspace One Content: before 3.21 (fixed in 3.21); before 4.20 (fixed in 4.20)
  • VMware Workspace One Intelligent Hub: before 19.11.1 (fixed in 19.11.1)
  • VMware Workspace One Notebook: before 1.2.1 (fixed in 1.2.1)
  • VMware Workspace One People: before 1.3.2 (fixed in 1.3.2)
  • VMware Workspace One Piv-D Manager: before 1.4.2 (fixed in 1.4.2)
  • VMware Workspace One SDK: before 1.4.1 (fixed in 1.4.1); before 1.5.1 (fixed in 1.5.1); from 19.8.0, before 19.11.1 (fixed in 19.11.1)
  • VMware Workspace One SDK (objective-C): from 5.9.9.7, before 5.9.9.8 (fixed in 5.9.9.8)
  • VMware Workspace One Web: before 7.10.8 (fixed in 7.10.8)

Published 2020-01-17. Last modified 2026-06-17.