Information Disclosure in VMware Aria Operations for Logs
CVE-2025-22218

8.5HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
30 January 2025

Badges

📰 News Worthy

Summary

VMware Aria Operations for Logs is affected by a vulnerability that allows unauthorized users with View Only Admin permissions to access sensitive credentials of integrated VMware products. This exposure can potentially lead to further exploitation of the system, compromising overall security and integrity.

Affected Version(s)

VMware Aria Operations for Logs any 8.x < 8.18.3

News Articles

Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft

Broadcom patches five VMware Aria Operations flaws, including CVE-2025-22218 (CVSS 8.5), preventing credential leaks and admin privilege abuse in vers

3 weeks ago

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.