Vulnerability Description
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Aria Automation | 8.18.0 |
| Vmware | Cloud Foundation | >= 4.0, <= 5.2.1 |
| Vmware | Telco Cloud Platform | >= 5.0, <= 5.0.1 |
Related Weaknesses (CWE)
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conPatchVendor Advisory
FAQ
What is CVE-2025-22249?
CVE-2025-22249 is a vulnerability with a CVSS score of 8.2 (HIGH). VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation a...
How severe is CVE-2025-22249?
CVE-2025-22249 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-22249?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Aria Automation, Vmware Cloud Foundation, Vmware Telco Cloud Platform.