CVE-2025-22222

V

Mware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*

History

14 May 2025, 16:47

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329 - Vendor Advisory
First Time Vmware cloud Foundation
Vmware
Vmware aria Operations

13 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-497
Summary
  • (es) VMware Aria Operations contiene una vulnerabilidad de divulgación de información. Un usuario malintencionado con privilegios no administrativos puede aprovechar esta vulnerabilidad para recuperar las credenciales de un complemento saliente si se conoce una ID de credencial de servicio válida.

30 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 16:15

Updated : 2025-05-14 16:47


NVD link : CVE-2025-22222

Mitre link : CVE-2025-22222

CVE.ORG link : CVE-2025-22222


JSON object : View

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere