Information Disclosure in VMware Aria Operations for Logs
CVE-2025-22218
7.7HIGH
What is CVE-2025-22218?
VMware Aria Operations for Logs is affected by a vulnerability that allows unauthorized users with View Only Admin permissions to access sensitive credentials of integrated VMware products. This exposure can potentially lead to further exploitation of the system, compromising overall security and integrity.
Affected Version(s)
VMware Aria Operations for Logs any 8.x < 8.18.3
News Articles

Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft
Broadcom patches five VMware Aria Operations flaws, including CVE-2025-22218 (CVSS 8.5), preventing credential leaks and admin privilege abuse in vers