CVE-2025-22221 Details
Description
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
A stored cross-site scripting vulnerability has been identified in VMware Aria Operations for Logs. This vulnerability allows a malicious actor with admin privileges to inject a script that could be executed in the browser of a victim performing a delete action in the Agent Configuration.
To address this vulnerability, users should apply the patch available in VMware Aria Operations for Logs version 8.18.3.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| vmware aria operations for logs | >= 8.0, < 8.18.3 |
CPE
Remediation
| |
| vmware cloud foundation | >= 4.0, <= 5.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2025 | Initial Analysis | [email protected] |
| Mar 13, 2025 | CVE Modified | CISA-ADP |
| Jan 30, 2025 | New CVE Received | [email protected] |