CVE-2025-22221
30.01.2025, 16:15
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability.A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
Vendor | Product | Version |
---|---|---|
vmware | aria_operations_for_logs | 8.0 ≤ 𝑥 < 8.18.3 |
vmware | cloud_foundation | 4.0 ≤ 𝑥 ≤ 5.2 |
𝑥
= Vulnerable software versions