CVE-2025-22220 is a privilege escalation vulnerability in VMware Aria Operations for Logs and VMware Cloud Foundation. A non-administrative attacker with network access to the API could perform actions as an administrator. Rated Medium (CVSS 5.4), this vulnerability has a low attack complexity and could lead to limited confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 8.18.3CPE matchmatch criteria | cpe:2.3:a:vmware:aria_operations_for_logs:*:*:*:*:*:*:*:* | ||
>= 4.0, <= 5.2CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities in VMware Aria Operations for logs and VMware Aria Operations
Jan 1, 2025Multiple vulnerabilities in VMware Aria Operations for Logs and VMware Aria Operations (VMSA-2025-0003)
Multiple vulnerabilities in VMware Aria Operations for Logs and VMware Aria Operations (VMSA-2025-0003)