CVE-2025-22249

EUVD-2025-14367
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
vmwareCNA
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
vmwarearia_automation
8.18.0
vmwarearia_automation
8.18.1
vmwarearia_automation
8.18.1:patch1
vmwarecloud_foundation
4.0 ≤
𝑥
≤ 5.2.1
vmwaretelco_cloud_platform
5.0 ≤
𝑥
≤ 5.0.1
𝑥
= Vulnerable software versions