CVE-2025-22243

Severity
7.5HIGH
EPSS
0.2%
top 61.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4

Description

VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:HExploitability: 1.7 | Impact: 5.3

Affected Packages5 packages

NVDbroadcom/vmware_nsx3.24.1.2.6+2
NVDvmware/cloud_foundation4.55.2.1.2
CVEListV5vmware/vmware_nsxVMware NSX 4.0.x, VMware NSX 4.1.x, VMware NSX 4.2.x

🔴Vulnerability Details

2
GHSA
GHSA-ccxh-4mwr-475q: VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation2025-06-04
CVEList
CVE-2025-22243: VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation2025-06-04

📋Vendor Advisories

1
Oracle
Oracle Oracle Retail Applications Risk Matrix: Point of Sale (Spring Framework) — CVE-2024-222432025-04-15