CVE-2025-22218: VMware Aria Operations for Logs information disclosure vulnerability
Published Jan 30, 2025
·Updated
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
Affected Software
3 affected components
VMware Aria Operations for Logs
VMware Aria Operations for Logs>=8.0<8.18.3
VMware Cloud Foundation>=4.0<=5.2
Event History
Jan 30, 2025
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverity
News Published
via The Register·10:00 PM
News Published
via The Register·10:04 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-22218?
CVE-2025-22218 is classified as an information disclosure vulnerability.
2
Who is affected by CVE-2025-22218?
CVE-2025-22218 affects VMware Aria Operations for Logs users with View Only Admin permissions.
3
What are the potential impacts of CVE-2025-22218?
The vulnerability may allow unauthorized access to read the credentials of integrated VMware products.
4
How do I fix CVE-2025-22218?
To remediate CVE-2025-22218, apply the latest security patches provided by VMware for Aria Operations for Logs.
5
Is there a workaround for CVE-2025-22218?
No effective workarounds have been documented for CVE-2025-22218 at this time.