• News/
  • https://www.theregister.com/2025/01/30/vmware_infomration_disclosure_flaws/

VMware plugs steal-my-credentials holes in Cloud Foundation

The Register
·
Jessica Lyons
·
Published Jan 30, 2025
·
Updated

Broadcom has fixed five flaws, collectively deemed "high severity," in VMware's IT operations and log management tools within Cloud Foundation, including two information disclosure bugs that could lead to credential leakage under certain conditions. All five have patches available. Broadcom's security advisory doesn't note any in-the-wild exploits, yet. We note that exploitation requires authorized access to vulnerable deployments, so if these are successfully abused in the wild, it'll most likely be through compromised or rogue accounts. The CVEs affect Aria Operations, used for managing IT operations across different environments, and Aria Operations for Logs, which is a tool for storing and analyzing log data. Both are pieces of VMware Cloud Foundation, meaning the bugs also affect versions 4.x and 5.x of the hybrid cloud platform. Specifically: Four of the vulnerabilities (CVE-2025-22218, CVE-2025-22219, CVE-2025-22220, and CVE-2025-22221) affect VMware Aria Operations for Logs versions 8 and newer, and one (CVE-2025-22222) affects the same versions of VMware Aria Operations. Updating both products to v8.18.3 will fix the issue. VMware Cloud Foundation users can follow KB92148 to apply the necessary fixes. The most severe of the bunch is CVE-2025-22218, an 8.5-rated information disclosure vulnerability in VMware Aria Operations for Logs. "A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria ...

Read full article

Affected Software

8 affected components
VMware Aria Operations=8
VMware Aria Operations for Logs=8
VMware Cloud Foundation=4.x
VMware Cloud Foundation=5.x
VMware Aria Operations=4.x
VMware Aria Operations=5.x
VMware Aria Operations for Logs=4.x
VMware Aria Operations for Logs=5.x
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What security vulnerabilities are addressed in the article about VMware?

The article discusses five high severity vulnerabilities in VMware's IT operations and log management tools, primarily focusing on two information disclosure flaws.

2

What are the potential consequences of the information disclosure flaws?

The information disclosure flaws could lead to credential leakage, allowing unauthorized access to sensitive information.

3

Which VMware products are affected by these security flaws?

The affected products include VMware Aria Operations, VMware Aria Operations for Logs, and VMware Cloud Foundation.

4

What versions of VMware products are impacted by the vulnerabilities?

The vulnerabilities affect VMware Aria Operations and VMware Aria Operations for Logs versions 4.x and 5.x, as well as VMware Cloud Foundation versions 4.x and 5.x.

5

How has VMware responded to these security issues?

VMware has released patches to address these vulnerabilities and enhance security in the affected product lines.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203