CVE-2023-20884: VMware Cloud Foundation

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

Affected products

  • VMware Cloud Foundation: affected versions not specified
  • VMware Identity Manager: version 3.3.6 only; version 3.3.7 only
  • VMware Identity Manager Connector: any version
  • VMware Workspace One Access: from 21.0.8.0, up to and including 22.09.1.0

Published 2023-05-30. Last modified 2026-06-17.