First published: Tue Jan 28 2025(Updated: )
Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. A malicious user with network access may be able to use specially crafted SQL queries to gain database access.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Avi Load Balancer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22217 is classified as a critical vulnerability due to its potential to allow unauthenticated access via SQL Injection.
To remediate CVE-2025-22217, apply the available patches provided by VMware for the affected versions of the Avi Load Balancer.
Exploitation of CVE-2025-22217 could allow an attacker to execute arbitrary SQL commands and potentially access sensitive data.
CVE-2025-22217 affects specific versions of VMware Avi Load Balancer, and it's recommended to check the VMware documentation for detailed version applicability.
No, exploitation of CVE-2025-22217 does not require authentication, making it particularly dangerous for exposed systems.