VMware plugs steal-my-credentials holes in Cloud Foundation
ID: 5e56259e-dfbc-5075-b6bd-0bade8636d6c
STIX ID: report--5e56259e-dfbc-5075-b6bd-0bade8636d6c
Feed Name: The Register (Security)
Broadcom patched five vulnerabilities in VMware Aria Operations and Aria Operations for Logs (components of VMware Cloud Foundation), including an 8.5-rated information disclosure (CVE-2025-22218), two stored XSS bugs (CVE-2025-22219, CVE-2025-22221), a privilege-escalation issue (CVE-2025-22220), and another information disclosure in Aria Operations (CVE-2025-22222); exploitation requires authorized or compromised accounts, no active exploitation has been reported, and updates/KB92148 provide fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
