VMware Workspace ONE Access validateClaimRuleCondition Remote OS Command Injection Webapp Exploit

This module exploits a custom java bean validator to deploy an agent in VMware Workspace ONE Access. The vulnerability is in the validateClaimRuleCondition function of ClaimTransformationHelper class. The deployed agent will run with horizon user privileges.
Exploit Platform
Product Name