CVE-2025-22249

VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:aria_automation:8.18.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_automation:8.18.1:-:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_automation:8.18.1:patch1:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*

History

11 Jul 2025, 14:27

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_automation:8.18.1:patch1:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_automation:8.18.1:-:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_automation:8.18.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
First Time Vmware telco Cloud Platform
Vmware
Vmware aria Automation
Vmware cloud Foundation
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25711 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25711 - Vendor Advisory, Patch

13 May 2025, 14:15

Type Values Removed Values Added
CWE CWE-79
Summary
  • (es) La automatización de VMware Aria contiene una vulnerabilidad de Cross Site Scripting (XSS) basada en DOM. Un atacante malicioso podría aprovechar esta vulnerabilidad para robar el token de acceso de un usuario conectado al dispositivo de automatización VMware Aria, engañándolo para que haga clic en una URL maliciosa.

13 May 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 06:15

Updated : 2025-07-11 14:27


NVD link : CVE-2025-22249

Mitre link : CVE-2025-22249

CVE.ORG link : CVE-2025-22249


JSON object : View

Products Affected

vmware

  • cloud_foundation
  • telco_cloud_platform
  • aria_automation
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')