CVE-2023-20884: VMware Cloud Foundation
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
Affected products
- VMware Cloud Foundation: affected versions not specified
- VMware Identity Manager: version 3.3.6 only; version 3.3.7 only
- VMware Identity Manager Connector: any version
- VMware Workspace One Access: from 21.0.8.0, up to and including 22.09.1.0
Published 2023-05-30. Last modified 2026-06-17.