CVE-2025-22222: VMware Aria Operations information disclosure vulnerability (CVE-2025-22222)
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-22222?
CVE-2025-22222 is classified as an information disclosure vulnerability.
How do I fix CVE-2025-22222?
To mitigate CVE-2025-22222, ensure that user permissions are properly configured to limit access to sensitive service credential IDs.
What can attackers do with CVE-2025-22222?
Attackers can exploit CVE-2025-22222 to retrieve credentials for an outbound plugin if they know a valid service credential ID.
Who is affected by CVE-2025-22222?
CVE-2025-22222 affects users of VMware Aria Operations, particularly those with non-administrative privileges.
Is there a workaround for CVE-2025-22222?
At this time, implementing strict access controls and auditing user permissions can serve as a temporary workaround for CVE-2025-22222.