CVE-2025-22221

Severity
4.8MEDIUM
EPSS
0.2%
top 52.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30

Description

VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:NExploitability: 0.9 | Impact: 4.2

Affected Packages3 packages

CVEListV5vmware/vmware_aria_operations_for_logs8.x8.18.3
NVDvmware/aria_operations8.08.18.3
NVDvmware/cloud_foundation4.05.2

🔴Vulnerability Details

2
CVEList
VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22221)2025-01-30
GHSA
GHSA-qrcx-78jp-35gm: VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability2025-01-30
CVE-2025-22221 (MEDIUM CVSS 4.8) | VMware Aria Operation for Logs cont | cvebase.io