First published: Thu Jan 30 2025(Updated: )
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Aria Operations |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-22222 is classified as an information disclosure vulnerability.
To mitigate CVE-2025-22222, ensure that user permissions are properly configured to limit access to sensitive service credential IDs.
Attackers can exploit CVE-2025-22222 to retrieve credentials for an outbound plugin if they know a valid service credential ID.
CVE-2025-22222 affects users of VMware Aria Operations, particularly those with non-administrative privileges.
At this time, implementing strict access controls and auditing user permissions can serve as a temporary workaround for CVE-2025-22222.