CVE-2025-22219

EUVD-2025-2675
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that  (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
vmwarearia_operations_for_logs
8.0 ≤
𝑥
< 8.18.3
vmwarecloud_foundation
4.0 ≤
𝑥
≤ 5.2
𝑥
= Vulnerable software versions