CVE-2025-22221: VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22221)
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-22221?
CVE-2025-22221 is classified as a stored cross-site scripting vulnerability, which can have a significant impact if exploited.
How do I fix CVE-2025-22221?
To fix CVE-2025-22221, it is recommended to update VMware Aria Operations for Logs to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-22221?
CVE-2025-22221 affects users of VMware Aria Operations for Logs who have admin privileges.
What type of vulnerability is CVE-2025-22221?
CVE-2025-22221 is a stored cross-site scripting vulnerability that allows a malicious actor to inject scripts.
What actions could exploit CVE-2025-22221?
CVE-2025-22221 can be exploited when an admin performs a delete action, potentially executing malicious scripts in a victim's browser.