CVE-2024-22280: VMSA-2024-0017: VMware Aria Automation updates address SQL-injection vulnerability (CVE-2024-22280)
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22280?
CVE-2024-22280 has been classified as a high-severity vulnerability due to its potential for SQL injection and unauthorized database access.
How do I fix CVE-2024-22280?
To fix CVE-2024-22280, it is recommended to update VMware Aria Automation and VMware Cloud Foundation to the latest patched versions.
Who is affected by CVE-2024-22280?
CVE-2024-22280 affects users of VMware Aria Automation versions prior to 8.17.0 and VMware Cloud Foundation versions between 4.0 and 5.0.
What kind of attacks can be performed using CVE-2024-22280?
An attacker exploiting CVE-2024-22280 can perform unauthorized read and write operations on the database through crafted SQL queries.
Is authentication required to exploit CVE-2024-22280?
Yes, exploitation of CVE-2024-22280 requires authentication, so only authenticated users can carry out the attack.