First published: Wed Jan 08 2025(Updated: )
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Aria automation |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22215 is categorized as a critical severity vulnerability due to its potential exploitation by unauthorized users.
To mitigate CVE-2025-22215, update VMware Aria Automation to the latest version provided by VMware.
Any user with 'Organization Member' access to VMware Aria Automation is potentially affected by CVE-2025-22215.
CVE-2025-22215 exploits a server-side request forgery (SSRF) vulnerability that allows enumeration of internal services.
The impact of CVE-2025-22215 includes unauthorized access to internal services, which could lead to further attacks on the network.