Server-Side Request Forgery in VMware Aria Automation
CVE-2025-22215
What is CVE-2025-22215?
VMware Aria Automation exposes a server-side request forgery (SSRF) vulnerability that allows a malicious actor with 'Organization Member' access to exploit the system. By leveraging this vulnerability, the actor can enumerate and potentially access sensitive internal services running on the host or network, which could lead to unauthorized data exposure and compromise of the environment. It is crucial for organizations using this product to assess their risk and implement necessary security measures to protect against exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
VMware Aria Automation any 8.x < 8.18.1 patch 1
VMware Cloud Foundation (VMware Aria Automation) Any 5.x < 8.18.1 patch 1
VMware Cloud Foundation (VMware Aria Automation) Any 4.x < 8.18.1 patch 1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved