Cyber Posture

CVE-2025-22222

High

Published: 30 January 2025

Published
30 January 2025
Modified
14 May 2025
KEV Added
Patch
CVSS Score 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score 0.0065 71.0th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.

Security Summary

CVE-2025-22222 is an information disclosure vulnerability in VMware Aria Operations. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. The issue is rated with a CVSS v3.1 base score of 7.7 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) and maps to CWE-497.

The vulnerability can be exploited by a malicious user possessing non-administrative privileges and network access to the affected system. Exploitation requires low complexity, no user interaction, and knowledge of a valid service credential ID. Successful attacks enable retrieval of sensitive credentials for outbound plugins, resulting in high confidentiality impact within a scoped environment.

Mitigation details are available in the Broadcom security advisory at https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329.

Details

CWE(s)
CWE-497

Affected Products

vmware
aria operations
8.0 — 8.18.3
vmware
cloud foundation
4.0 — 5.2

References