CVE-2025-22222
CVSS 3.1 Score 7.7 of 10 (high)
Details
Summary
CVE-2025-22222 is a newly disclosed information disclosure vulnerability in VMware Aria Operations. This issue allows non-administrative users to access credentials for outbound plugins if they have knowledge of a valid service credential ID. Exploitation of this vulnerability could potentially lead to unauthorized access to sensitive information. VMware urges users to apply the available patch to mitigate this risk. The vulnerability does not require elevated privileges to exploit, making it a significant security concern for organizations using VMware Aria Operations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- VMware Aria Operations
Affected Vendors
- VMware Inc.