<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">
  <channel>
    <title>VMSA-2022-0028</title>
    <language>en-US</language>
    <pubDate>Fri, 20 Oct 2023 18:52:34 PDT</pubDate>
    <lastBuildDate>Fri, 20 Oct 2023 18:52:34 PDT</lastBuildDate>
    <link>https://www.vmware.com/security/advisories/VMSA-2022-0028.html</link>
    <sy:updatePeriod>hourly</sy:updatePeriod>
    <sy:updateFrequency>1</sy:updateFrequency>
    <item>
      <title>VMSA-2022-0028</title>
      <pubDate>Fri, 20 Oct 2023 18:52:34 PDT</pubDate>
      <description>
        <![CDATA[<div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> 
 <div class="responsivegrid aem-GridColumn aem-GridColumn--default--12"> 
  <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> 
   <div class="advisories-summary aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/advisories-summary/clientlibs.min.css" type="text/css">  
    <section class="sa-detail-wrapper section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <div class="sa-image-block"> 
          <div class="sa-severity"> 
           <div class="sa-critical"> 
            <p>Critical</p> 
           </div> 
          </div> 
         </div> 
         <div class="sa-detail-block"> 
          <div class="col-md-8"> 
           <div class="sa-details"> 
            <div class="sa-row-group"> 
             <label>Advisory ID:</label> 
             <span>VMSA-2022-0028</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>CVSSv3 Range:</label> 
             <span>4.2-9.8</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Issue Date:</label> 
             <span>2022-11-08</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Updated On:</label> 
             <span>2022-11-08 (Initial Advisory)</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>CVE(s):</label> 
             <span>CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Synopsis:</label> 
             <span>VMware Workspace ONE Assist update addresses multiple vulnerabilities.</span> 
            </div> 
           </div> 
          </div> 
          <div class="col-md-4 sa-summary-link-section" data-html2canvas-ignore="true">  
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/secadvheading/clientlibs.min.css" type="text/css"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>1. Impacted Products</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <ul> 
             <li>VMware Workspace ONE Assist (Assist)</li> 
            </ul> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>2. Introduction</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Multiple vulnerabilities in VMware Workspace ONE Assist were privately reported to VMware. Patches are available to remediate these vulnerabilities in affected VMware products.&nbsp;</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3a. Authentication Bypass vulnerability (CVE-2022-31685)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains an Authentication Bypass vulnerability.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">9.8</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31685 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3b. Broken Authentication Method vulnerability (CVE-2022-31686)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains a Broken Authentication Method vulnerability.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">9.8</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor with network access may be able to obtain administrative access without the need to authenticate to the application.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31686 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3c. Broken Access Control vulnerability (CVE-2022-31687)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains a Broken Access Control vulnerability.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">9.8</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor with network access may be able to obtain administrative access without the need to authenticate to the application.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31687 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3d. Reflected cross-site scripting (XSS) vulnerability (CVE-2022-31688)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains a&nbsp;reflected&nbsp;cross-site scripting (XSS) vulnerability.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Moderate severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L">6.4</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31688 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3e. Session fixation vulnerability (CVE-2022-31689)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains a session fixation vulnerability due to improper handling of session tokens.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Moderate severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N">4.2</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31689 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Response Matrix 3a, 3b, 3c, 3d, 3e:</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="advisories-data aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/advisories-data/clientlibs.min.css" type="text/css"> 
    <section class="response-matrix"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <div class="section-custom"> 
          <div class="table-responsive"> 
           <table class="table"> 
            <tbody>
             <tr class="tr thead"> 
              <td class="td">Product</td> 
              <td class="td">Version</td> 
              <td class="td">Running On</td> 
              <td class="td">CVE Identifier</td> 
              <td class="td">CVSSv3</td> 
              <td class="td">Severity</td> 
              <td class="td">Fixed Version</td> 
              <td class="td">Workarounds</td> 
              <td class="td">Additional Documentation</td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist Server(s) 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                21.x, 22.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="4.2 - 9.8" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N">4.2 - 9.8</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                22.10
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                <a aria-label="KB89993" href="https://kb.vmware.com/s/article/89993">KB89993</a>
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for macOS 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                macOS
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for Android 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Android
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for Windows Desktop (Formerly Windows 10 Desktop) 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for Windows Mobile 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows Mobile
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for VMware Horizon - Windows 10 Agent 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for Linux 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Linux
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
            </tbody>
           </table> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>4. References</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><b>Fixed Version(s) and Release Notes:<br> </b><span style="">VMware Workspace ONE Assist Release Notes&nbsp;</span><a href="https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/services/rn/vmware-workspace-one-assist-release-notes/index.html">https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/services/rn/vmware-workspace-one-assist-release-notes/index.html</a></p> 
            <p><b>Additional Documentation:<br> </b><span style="">Introducing Workspace ONE Assist 22.10 (89993)&nbsp;</span><a href="https://kb.vmware.com/s/article/89993">https://kb.vmware.com/s/article/89993</a></p> 
            <p><b>Mitre CVE Dictionary Links:<br> </b><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31685">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31685</a><br> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31686">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31686</a><br> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31687">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31687</a><br> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31688">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31688</a><br> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31689">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31689</a></p> 
            <p><b>FIRST CVSSv3 Calculator:<br> </b><span style="">CVE-2022-31685:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a><br> <span style="">CVE-2022-31686:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a><br> <span style="">CVE-2022-31687:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a><br> <span style="">CVE-2022-31688:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L</a><br> <span style="">CVE-2022-31689:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N</a></p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>5. Change Log</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><b>2022-11-08: VMSA-2022-0028</b><br> Initial security advisory.</p> 
            <p>&nbsp;</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>6. Contact</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>E-mail list for product security notifications and announcements:</p> 
            <p><a href="https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce">https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>This Security Advisory is posted to the following lists:&nbsp;&nbsp;</p> 
            <p><a href="mailto:security-announce@lists.vmware.com">security-announce@lists.vmware.com&nbsp;&nbsp;</a></p> 
            <p><a href="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com&nbsp;&nbsp;</a></p> 
            <p><a href="mailto:fulldisclosure@seclists.org">fulldisclosure@seclists.org&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>E-mail: <a href="mailto:security@vmware.com">security@vmware.com</a></p> 
            <p>PGP key at:</p> 
            <p><a href="https://kb.vmware.com/kb/1055">https://kb.vmware.com/kb/1055&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security Advisories</p> 
            <p><a href="https://www.vmware.com/security/advisories">https://www.vmware.com/security/advisories&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security Response Policy</p> 
            <p><a href="https://www.vmware.com/support/policies/security_response.html">https://www.vmware.com/support/policies/security_response.html&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Lifecycle Support Phases</p> 
            <p><a href="https://www.vmware.com/support/policies/lifecycle.html">https://www.vmware.com/support/policies/lifecycle.html&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security &amp; Compliance Blog&nbsp;&nbsp;</p> 
            <p><a href="https://blogs.vmware.com/security">https://blogs.vmware.com/security&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>Twitter</p> 
            <p><a href="https://twitter.com/VMwareSRC">https://twitter.com/VMwareSRC<br> </a></p> 
            <p>&nbsp;</p> 
            <p>Copyright 2022 VMware Inc. All rights reserved.<br> &nbsp;<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
  </div> 
 </div> 
</div>]]>
      </description>
      <content:encoded>
        <![CDATA[<div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> 
 <div class="responsivegrid aem-GridColumn aem-GridColumn--default--12"> 
  <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> 
   <div class="advisories-summary aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/advisories-summary/clientlibs.min.css" type="text/css">  
    <section class="sa-detail-wrapper section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <div class="sa-image-block"> 
          <div class="sa-severity"> 
           <div class="sa-critical"> 
            <p>Critical</p> 
           </div> 
          </div> 
         </div> 
         <div class="sa-detail-block"> 
          <div class="col-md-8"> 
           <div class="sa-details"> 
            <div class="sa-row-group"> 
             <label>Advisory ID:</label> 
             <span>VMSA-2022-0028</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>CVSSv3 Range:</label> 
             <span>4.2-9.8</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Issue Date:</label> 
             <span>2022-11-08</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Updated On:</label> 
             <span>2022-11-08 (Initial Advisory)</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>CVE(s):</label> 
             <span>CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Synopsis:</label> 
             <span>VMware Workspace ONE Assist update addresses multiple vulnerabilities.</span> 
            </div> 
           </div> 
          </div> 
          <div class="col-md-4 sa-summary-link-section" data-html2canvas-ignore="true">  
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/secadvheading/clientlibs.min.css" type="text/css"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>1. Impacted Products</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <ul> 
             <li>VMware Workspace ONE Assist (Assist)</li> 
            </ul> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>2. Introduction</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Multiple vulnerabilities in VMware Workspace ONE Assist were privately reported to VMware. Patches are available to remediate these vulnerabilities in affected VMware products.&nbsp;</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3a. Authentication Bypass vulnerability (CVE-2022-31685)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains an Authentication Bypass vulnerability.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">9.8</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31685 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3b. Broken Authentication Method vulnerability (CVE-2022-31686)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains a Broken Authentication Method vulnerability.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">9.8</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor with network access may be able to obtain administrative access without the need to authenticate to the application.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31686 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3c. Broken Access Control vulnerability (CVE-2022-31687)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains a Broken Access Control vulnerability.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">9.8</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor with network access may be able to obtain administrative access without the need to authenticate to the application.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31687 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3d. Reflected cross-site scripting (XSS) vulnerability (CVE-2022-31688)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains a&nbsp;reflected&nbsp;cross-site scripting (XSS) vulnerability.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Moderate severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L">6.4</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31688 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3e. Session fixation vulnerability (CVE-2022-31689)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Workspace ONE Assist contains a session fixation vulnerability due to improper handling of session tokens.&nbsp;VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Moderate severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N">4.2</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixes for CVE-2022-31689 are documented in the 'Fixed Version' column of the 'Response Matrix' below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><a href="https://kb.vmware.com/s/article/89993">Introducing Workspace ONE Assist 22.10 (89993)</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of&nbsp;<a href="https://reqon.nl">REQON B.V.</a> for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Response Matrix 3a, 3b, 3c, 3d, 3e:</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="advisories-data aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/advisories-data/clientlibs.min.css" type="text/css"> 
    <section class="response-matrix"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <div class="section-custom"> 
          <div class="table-responsive"> 
           <table class="table"> 
            <tbody>
             <tr class="tr thead"> 
              <td class="td">Product</td> 
              <td class="td">Version</td> 
              <td class="td">Running On</td> 
              <td class="td">CVE Identifier</td> 
              <td class="td">CVSSv3</td> 
              <td class="td">Severity</td> 
              <td class="td">Fixed Version</td> 
              <td class="td">Workarounds</td> 
              <td class="td">Additional Documentation</td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist Server(s) 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                21.x, 22.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="4.2 - 9.8" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N">4.2 - 9.8</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                22.10
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                <a aria-label="KB89993" href="https://kb.vmware.com/s/article/89993">KB89993</a>
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for macOS 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                macOS
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for Android 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Android
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for Windows Desktop (Formerly Windows 10 Desktop) 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for Windows Mobile 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows Mobile
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for VMware Horizon - Windows 10 Agent 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                Assist for Linux 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                Any
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Linux
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-31685, CVE-2022-31686, CVE-2022-31687, CVE-2022-31688, CVE-2022-31689
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 N/A
                </div> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                Unaffected
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                N/A
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                N/A
               </div> </td> 
             </tr> 
            </tbody>
           </table> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>4. References</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><b>Fixed Version(s) and Release Notes:<br> </b><span style="">VMware Workspace ONE Assist Release Notes&nbsp;</span><a href="https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/services/rn/vmware-workspace-one-assist-release-notes/index.html">https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/services/rn/vmware-workspace-one-assist-release-notes/index.html</a></p> 
            <p><b>Additional Documentation:<br> </b><span style="">Introducing Workspace ONE Assist 22.10 (89993)&nbsp;</span><a href="https://kb.vmware.com/s/article/89993">https://kb.vmware.com/s/article/89993</a></p> 
            <p><b>Mitre CVE Dictionary Links:<br> </b><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31685">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31685</a><br> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31686">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31686</a><br> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31687">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31687</a><br> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31688">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31688</a><br> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31689">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31689</a></p> 
            <p><b>FIRST CVSSv3 Calculator:<br> </b><span style="">CVE-2022-31685:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a><br> <span style="">CVE-2022-31686:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a><br> <span style="">CVE-2022-31687:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a><br> <span style="">CVE-2022-31688:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L</a><br> <span style="">CVE-2022-31689:&nbsp;</span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N</a></p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>5. Change Log</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p><b>2022-11-08: VMSA-2022-0028</b><br> Initial security advisory.</p> 
            <p>&nbsp;</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>6. Contact</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>E-mail list for product security notifications and announcements:</p> 
            <p><a href="https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce">https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>This Security Advisory is posted to the following lists:&nbsp;&nbsp;</p> 
            <p><a href="mailto:security-announce@lists.vmware.com">security-announce@lists.vmware.com&nbsp;&nbsp;</a></p> 
            <p><a href="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com&nbsp;&nbsp;</a></p> 
            <p><a href="mailto:fulldisclosure@seclists.org">fulldisclosure@seclists.org&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>E-mail: <a href="mailto:security@vmware.com">security@vmware.com</a></p> 
            <p>PGP key at:</p> 
            <p><a href="https://kb.vmware.com/kb/1055">https://kb.vmware.com/kb/1055&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security Advisories</p> 
            <p><a href="https://www.vmware.com/security/advisories">https://www.vmware.com/security/advisories&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security Response Policy</p> 
            <p><a href="https://www.vmware.com/support/policies/security_response.html">https://www.vmware.com/support/policies/security_response.html&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Lifecycle Support Phases</p> 
            <p><a href="https://www.vmware.com/support/policies/lifecycle.html">https://www.vmware.com/support/policies/lifecycle.html&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security &amp; Compliance Blog&nbsp;&nbsp;</p> 
            <p><a href="https://blogs.vmware.com/security">https://blogs.vmware.com/security&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>Twitter</p> 
            <p><a href="https://twitter.com/VMwareSRC">https://twitter.com/VMwareSRC<br> </a></p> 
            <p>&nbsp;</p> 
            <p>Copyright 2022 VMware Inc. All rights reserved.<br> &nbsp;<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
  </div> 
 </div> 
</div>]]>
      </content:encoded>
      <link>https://www.vmware.com/security/advisories/VMSA-2022-0028.html</link>
    </item>
  </channel>
</rss>
