VMware Workspace ONE Access, Identity Manager, and Realize Automation are vulnerable to local file inclusion because they contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
id: CVE-2022-31656
info:
name: VMware - Local File Inclusion
author: DhiyaneshDk
severity: cr
...