CVE-2025-22215

VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
Configurations

No configuration.

History

08 Jan 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) VMware Aria Automation contiene una vulnerabilidad de server-side request forgery (SSRF) . Un actor malintencionado con acceso de "miembro de la organización" a Aria Automation puede aprovechar esta vulnerabilidad para enumerar los servicios internos que se ejecutan en el host o la red.
CWE CWE-918

08 Jan 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-08 07:15

Updated : 2025-01-08 15:15


NVD link : CVE-2025-22215

Mitre link : CVE-2025-22215

CVE.ORG link : CVE-2025-22215


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)