DOM-Based Cross-Site Scripting Vulnerability in VMware Aria Automation
CVE-2025-22249

8.2HIGH

Key Information:

What is CVE-2025-22249?

VMware Aria Automation is vulnerable to a DOM-based Cross-Site Scripting (XSS) issue, where a malicious actor can exploit this weakness by luring users into clicking on a specially crafted URL. This can potentially allow the attacker to hijack the access token of users logged into the VMware Aria Automation appliance, leading to unauthorized access and data compromise.

Affected Version(s)

Vmware Aria Automation any 8.18.x < 8.18.1 patch2

VMware Cloud Foundation any 5.x < 8.18.1 patch 2

VMware Cloud Foundation any 4.x < 8.18.1 patch 2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22249 : DOM-Based Cross-Site Scripting Vulnerability in VMware Aria Automation