CVE-2025-22215: VMSA-2025-0001: VMware Aria automation update addresses a server side request forgery vulnerability (CVE-2025-22215)
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22215?
CVE-2025-22215 is categorized as a critical severity vulnerability due to its potential exploitation by unauthorized users.
How do I fix CVE-2025-22215?
To mitigate CVE-2025-22215, update VMware Aria Automation to the latest version provided by VMware.
Who is affected by CVE-2025-22215?
Any user with 'Organization Member' access to VMware Aria Automation is potentially affected by CVE-2025-22215.
What does CVE-2025-22215 exploit?
CVE-2025-22215 exploits a server-side request forgery (SSRF) vulnerability that allows enumeration of internal services.
What is the impact of CVE-2025-22215?
The impact of CVE-2025-22215 includes unauthorized access to internal services, which could lead to further attacks on the network.