Publisher not identified
VMware Workspace ONE UEM Console
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2023-20886 | 31 Oct 2023 | Workspace ONE UEM 23.2.0.0; Workspace ONE UEM 22.12.0.0; Workspace ONE UEM 22.9.0.0; Workspace ONE UEM 22.6.0.0; Workspace ONE UEM 22.3.0.0 | Workspace ONE UEM 23.6.0.0 | Update reference ↗ |
| CVE-2021-22029 | 31 Aug 2021 | Workspace ONE UEM console 2105, 2102, 2011, 2008, 2005 & 2001 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-21990 | 11 May 2021 | VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 2003 prior to 20.3.0.23, 2001 prior to 20.1.0.32, 1912 prior to 19.12.0.24) | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.