CVE-2025-22220

MEDIUM

VMware Aria Operations for Logs - Privilege Escalation

Title source: llm
STIX 2.1

Description

VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 35.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
vmware/aria_operations_for_logs 8.0 - 8.18.3
vmware/cloud_foundation 4.0 - 5.2
Published Jan 30, 2025
Tracked Since Feb 18, 2026