CVE-2025-22218

VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:aria_operations_for_logs:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*

History

14 May 2025, 16:45

Type Values Removed Values Added
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329 - Vendor Advisory
CPE cpe:2.3:a:vmware:aria_operations_for_logs:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
First Time Vmware cloud Foundation
Vmware
Vmware aria Operations For Logs

13 Mar 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) VMware Aria Operations for Logs contiene una vulnerabilidad de divulgación de información. Un actor malintencionado con permisos de administrador de solo lectura podría leer las credenciales de un producto VMware integrado con VMware Aria Operations for Logs
CWE CWE-209

30 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 15:15

Updated : 2025-05-14 16:45


NVD link : CVE-2025-22218

Mitre link : CVE-2025-22218

CVE.ORG link : CVE-2025-22218


JSON object : View

Products Affected

vmware

  • aria_operations_for_logs
  • cloud_foundation
CWE
CWE-209

Generation of Error Message Containing Sensitive Information