Broadcom has fixed five flaws, collectively deemed "high severity," in VMware's IT operations and log management tools within Cloud Foundation, including two information disclosure bugs that could lead to credential leakage under certain conditions. All five have patches available. Broadcom's security advisory doesn't note any in-the-wild exploits, yet. We note that exploitation requires authorized access to vulnerable deployments, so if these are successfully abused in the wild, it'll most likely be through compromised or rogue accounts. The CVEs affect Aria Operations, used for managing IT operations across different environments, and Aria Operations for Logs, which is a tool for storing and analyzing log data. Both are pieces of VMware Cloud Foundation, meaning the bugs also affect versions 4.x and 5.x of the hybrid cloud platform. Specifically: Four of the vulnerabilities (CVE-2025-22218, CVE-2025-22219, CVE-2025-22220, and CVE-2025-22221) affect VMware Aria Operations for Logs versions 8 and newer, and one (CVE-2025-22222) affects the same versions of VMware Aria Operations. Updating both products to v8.18.3 will fix the issue. VMware Cloud Foundation users can follow KB92148 to apply the necessary fixes. The most severe of the bunch is CVE-2025-22218, an 8.5-rated information disclosure vulnerability in VMware Aria Operations for Logs. "A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria ...
VMware plugs steal-my-credentials holes in Cloud Foundation
The Register
·Jessica Lyons
·Published Jan 30, 2025
·Updated
Affected Software
8 affected components
VMware Aria Operations=8
VMware Aria Operations for Logs=8
VMware Cloud Foundation=4.x
VMware Cloud Foundation=5.x
VMware Aria Operations=4.x
VMware Aria Operations=5.x
VMware Aria Operations for Logs=4.x
VMware Aria Operations for Logs=5.x
Frequently Asked Questions
1
What security vulnerabilities are addressed in the article about VMware?
The article discusses five high severity vulnerabilities in VMware's IT operations and log management tools, primarily focusing on two information disclosure flaws.
2
What are the potential consequences of the information disclosure flaws?
The information disclosure flaws could lead to credential leakage, allowing unauthorized access to sensitive information.
3
Which VMware products are affected by these security flaws?
The affected products include VMware Aria Operations, VMware Aria Operations for Logs, and VMware Cloud Foundation.
4
What versions of VMware products are impacted by the vulnerabilities?
The vulnerabilities affect VMware Aria Operations and VMware Aria Operations for Logs versions 4.x and 5.x, as well as VMware Cloud Foundation versions 4.x and 5.x.
5
How has VMware responded to these security issues?
VMware has released patches to address these vulnerabilities and enhance security in the affected product lines.