{"id":75953,"date":"2022-04-07T03:55:16","date_gmt":"2022-04-07T05:55:16","guid":{"rendered":"https:\/\/teknomers.com\/fr\/vmware-publie-des-correctifs-critiques-pour-les-nouvelles-vulnerabilites-affectant-plusieurs-produits\/"},"modified":"2022-04-07T03:55:23","modified_gmt":"2022-04-07T05:55:23","slug":"vmware-publie-des-correctifs-critiques-pour-les-nouvelles-vulnerabilites-affectant-plusieurs-produits","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/vmware-publie-des-correctifs-critiques-pour-les-nouvelles-vulnerabilites-affectant-plusieurs-produits\/","title":{"rendered":"VMware publie des correctifs critiques pour les nouvelles vuln\u00e9rabilit\u00e9s affectant plusieurs produits"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>VMware a publi\u00e9 des mises \u00e0 jour de s\u00e9curit\u00e9 pour corriger huit vuln\u00e9rabilit\u00e9s couvrant ses produits, dont certaines pourraient \u00eatre exploit\u00e9es pour lancer des attaques d&#8217;ex\u00e9cution de code \u00e0 distance.<\/p>\n<p>Suivi depuis <a rel=\"nofollow noopener\" href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0011.html\" target=\"_blank\">CVE-2022-22954 \u00e0 CVE-2022-22961<\/a> (scores CVSS\u00a0: 5,3 &#8211; 9,8), les probl\u00e8mes affectent VMware Workspace ONE Access, VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation et vRealize Suite Lifecycle Manager.<\/p>\n<p>Cinq des huit bogues sont class\u00e9s critiques, deux sont class\u00e9s importants et un est class\u00e9 mod\u00e9r\u00e9 en gravit\u00e9.  Steven Seeley de Qihoo 360 Vulnerability Research Institute est cr\u00e9dit\u00e9 d&#8217;avoir signal\u00e9 toutes les vuln\u00e9rabilit\u00e9s.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-d3\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Des-pirates-informatiques-iraniens-utilisent-un-nouveau-logiciel-malveillant-despionnage.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>La liste des d\u00e9fauts est ci-dessous &#8211;<\/p>\n<ul>\n<li><strong>CVE-2022-22954<\/strong> (Score CVSS : 9,8) &#8211; Vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance par injection de mod\u00e8le c\u00f4t\u00e9 serveur affectant VMware Workspace ONE Access et Identity Manager<\/li>\n<li><strong>CVE-2022-22955 et CVE-2022-22956<\/strong> (Scores CVSS\u00a0: 9,8) &#8211; Vuln\u00e9rabilit\u00e9s de contournement de l&#8217;authentification OAuth2 ACS dans VMware Workspace ONE Access<\/li>\n<li><strong>CVE-2022-22957 et CVE-2022-22958<\/strong> (Scores CVSS\u00a0: 9,1) &#8211; Vuln\u00e9rabilit\u00e9s d&#8217;ex\u00e9cution de code \u00e0 distance par injection JDBC dans VMware Workspace ONE Access, Identity Manager et vRealize Automation<\/li>\n<li><strong>CVE-2022-22959<\/strong> (Score CVSS\u00a0: 8,8) &#8211; Vuln\u00e9rabilit\u00e9 de falsification de requ\u00eate intersite (CSRF) dans VMware Workspace ONE Access, Identity Manager et vRealize Automation<\/li>\n<li><strong>CVE-2022-22960<\/strong> (Score CVSS\u00a0: 7,8) &#8211; Vuln\u00e9rabilit\u00e9 d&#8217;\u00e9l\u00e9vation des privil\u00e8ges locaux dans VMware Workspace ONE Access, Identity Manager et vRealize Automation, et<\/li>\n<li><strong>CVE-2022-22961<\/strong> (Score CVSS : 5,3) &#8211; Vuln\u00e9rabilit\u00e9 de divulgation d&#8217;informations affectant VMware Workspace ONE Access, Identity Manager et vRealize Automation<\/li>\n<\/ul>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>L&#8217;exploitation r\u00e9ussie des faiblesses susmentionn\u00e9es pourrait permettre \u00e0 un acteur malveillant d&#8217;\u00e9lever les privil\u00e8ges \u00e0 l&#8217;utilisateur root, d&#8217;acc\u00e9der aux noms d&#8217;h\u00f4te des syst\u00e8mes cibles et d&#8217;ex\u00e9cuter \u00e0 distance du code arbitraire, permettant ainsi une prise de contr\u00f4le compl\u00e8te.<\/p>\n<p>\u00ab Cette vuln\u00e9rabilit\u00e9 critique doit \u00eatre corrig\u00e9e ou att\u00e9nu\u00e9e imm\u00e9diatement \u00bb, VMware <a rel=\"nofollow noopener\" href=\"https:\/\/core.vmware.com\/vmsa-2022-0011-questions-answers-faq\" target=\"_blank\">mentionn\u00e9<\/a> dans une alerte.  &#8220;Les ramifications de cette vuln\u00e9rabilit\u00e9 sont graves.&#8221;<\/p>\n<p>Bien que le fournisseur de services de virtualisation ait not\u00e9 qu&#8217;il n&#8217;avait vu aucune preuve que les vuln\u00e9rabilit\u00e9s aient \u00e9t\u00e9 exploit\u00e9es \u00e0 l&#8217;\u00e9tat sauvage, il est fortement recommand\u00e9 d&#8217;appliquer les correctifs pour supprimer les menaces potentielles.<\/p>\n<p>&#8220;Les solutions de contournement, bien que pratiques, ne suppriment pas les vuln\u00e9rabilit\u00e9s et peuvent introduire des complexit\u00e9s suppl\u00e9mentaires que les correctifs ne feraient pas&#8221;, a averti la soci\u00e9t\u00e9.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/vmware-releases-critical-patches-for.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>VMware a publi\u00e9 des mises \u00e0 jour de s\u00e9curit\u00e9 pour corriger huit vuln\u00e9rabilit\u00e9s couvrant ses produits, dont certaines pourraient \u00eatre exploit\u00e9es pour lancer des attaques d&#8217;ex\u00e9cution de code \u00e0 distance. Suivi depuis CVE-2022-22954 \u00e0 CVE-2022-22961 (scores CVSS\u00a0: 5,3 &#8211; 9,8), les probl\u00e8mes affectent VMware Workspace ONE Access, VMware Identity Manager, VMware vRealize Automation, VMware Cloud [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":75954,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[34911,4168,15954,5729,4158,4165,4161,133,4157,4159,4171,4170,65,4167,4160,120,4163,4162,701,185,2726,2212,4172,4169,4166,34910,4164,12365],"class_list":["post-75953","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-affectant","tag-comment-pirater","tag-correctifs","tag-critiques","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-plusieurs","tag-pour","tag-produits","tag-publie","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vmware","tag-vulnerabilite-logicielle","tag-vulnerabilites"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/75953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=75953"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/75953\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/75954"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=75953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=75953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=75953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}