DOM-Based Cross-Site Scripting Vulnerability in VMware Aria Automation
CVE-2025-22249
8.2HIGH
What is CVE-2025-22249?
VMware Aria Automation is vulnerable to a DOM-based Cross-Site Scripting (XSS) issue, where a malicious actor can exploit this weakness by luring users into clicking on a specially crafted URL. This can potentially allow the attacker to hijack the access token of users logged into the VMware Aria Automation appliance, leading to unauthorized access and data compromise.
Affected Version(s)
Vmware Aria Automation any 8.18.x < 8.18.1 patch2
VMware Cloud Foundation any 5.x < 8.18.1 patch 2
VMware Cloud Foundation any 4.x < 8.18.1 patch 2
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved