Vmware Aria Operations For Logs vulnerabilities

4 known vulnerabilities affecting vmware/vmware_aria_operations_for_logs.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-22219CRITICALCVSS 9.0≥ 8.x, < 8.18.32025-01-30
CVE-2025-22219 [MEDIUM] CWE-79 CVE-2025-22219: VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious ac VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
cvelistv5nvd
CVE-2025-22218HIGHCVSS 7.7≥ 8.x, < 8.18.32025-01-30
CVE-2025-22218 [HIGH] CWE-209 CVE-2025-22218: VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
cvelistv5nvd
CVE-2025-22221MEDIUMCVSS 4.8≥ 8.x, < 8.18.32025-01-30
CVE-2025-22221 [MEDIUM] CWE-79 CVE-2025-22221: VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious act VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
cvelistv5nvd
CVE-2025-22220MEDIUMCVSS 5.4≥ 8.x, < 8.18.32025-01-30
CVE-2025-22220 [MEDIUM] CWE-269 CVE-2025-22220: VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor wit VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.
cvelistv5nvd