<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									VMSA-2025-0003 VMware Aria Operations for Logs and VMware Aria Operations vulnerability PATCH NOW! - Cybersecurity Forum				            </title>
            <link>https://www.virtualizationhowto.com/community/cybersecurity-forum/vmsa-2025-0003-vmware-aria-operations-for-logs-and-vmware-aria-operations-vulnerability-patch-now/</link>
            <description>Virtualization Howto Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Tue, 12 May 2026 15:35:51 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>VMSA-2025-0003 VMware Aria Operations for Logs and VMware Aria Operations vulnerability PATCH NOW!</title>
                        <link>https://www.virtualizationhowto.com/community/cybersecurity-forum/vmsa-2025-0003-vmware-aria-operations-for-logs-and-vmware-aria-operations-vulnerability-patch-now/#post-1154</link>
                        <pubDate>Thu, 30 Jan 2025 16:32:53 +0000</pubDate>
                        <description><![CDATA[It seems like these vulnerabilities will never end, but here is another one that VIAdmins need to give attention to. This new high severity vulnerability affects two of the Aria products acr...]]></description>
                        <content:encoded><![CDATA[<p>It seems like these vulnerabilities will never end, but here is another one that VIAdmins need to give attention to. This new high severity vulnerability affects two of the Aria products across the Aria solution line, including: <strong>VMware Aria Operations for Logs and VMware Aria Operations and since these are included in VCF, it also affects VCF</strong>.</p>
500
<p>What can the vulnerabilities lead to? Note the following that are listed in the official VMSA thred </p>
<ul>
<li><strong>information disclosure, privilege escalation, and cross-site scripting (XSS) attacks</strong></li>
</ul>
Note the following affected vulnerabilities:<br />
<h3><strong>&#x1f534; Affected Vulnerabilities</strong></h3>
<table>
<thead>
<tr>
<th><strong>CVE ID</strong></th>
<th><strong>Impact</strong></th>
<th><strong>CVSS Score</strong></th>
<th><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>CVE-2025-22218</strong></td>
<td>Information Disclosure</td>
<td>8.5 (High)</td>
<td>Attackers with View Only Admin permissions can read stored credentials.</td>
</tr>
<tr>
<td><strong>CVE-2025-22219</strong></td>
<td>Stored Cross-Site Scripting (XSS)</td>
<td>6.8 (Moderate)</td>
<td>Non-admin users can inject scripts, leading to arbitrary operations as an admin.</td>
</tr>
<tr>
<td><strong>CVE-2025-22220</strong></td>
<td>Broken Access Control</td>
<td>4.3 (Moderate)</td>
<td>Non-admin users can execute privileged API operations as an admin.</td>
</tr>
<tr>
<td><strong>CVE-2025-22221</strong></td>
<td>Stored Cross-Site Scripting (XSS)</td>
<td>5.2 (Moderate)</td>
<td>Admins can inject scripts that execute when performing delete actions.</td>
</tr>
<tr>
<td><strong>CVE-2025-22222</strong></td>
<td>Information Disclosure</td>
<td>7.7 (High)</td>
<td>Attackers can retrieve credentials for outbound plugins if they know a valid service credential ID.</td>
</tr>
</tbody>
</table>
<h3><strong>&#x1f6e0;&#xfe0f; Resolution: Apply Security Patches ASAP</strong></h3>
<p>As a note, there are no workarounds. Here are the patched versions:</p>
<ul>
<li><strong>VMware Aria Operations for Logs:</strong> <strong>8.18.3</strong></li>
<li><strong>VMware Aria Operations:</strong> <strong>8.18.3</strong></li>
<li><strong>VMware Cloud Foundation:</strong> <strong>KB92148</strong></li>
</ul>
<p>&#x1f517; <strong>Patch Links &amp; Documentation:</strong></p>
<ul>
<li><a href="https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations-for-logs/8-18/vmware-aria-operations-for-logs-8183-release-notes.html" target="_new" rel="noopener"><span>VMware</span><span> Aria</span><span> Operations</span><span> for</span><span> Logs</span><span> 8.18.3</span><span> Release</span><span> Notes</span></a></li>
<li><a href="https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations/8-18/vmware-aria-operations-8183-release-notes.html" target="_new" rel="noopener"><span>VMware</span><span> Aria</span><span> Operations</span><span> 8.18.3</span><span> Release</span><span> Notes</span></a></li>
</ul>
<p>For the deets on the info, you can see the official advisory here:</p>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22218" target="_new" rel="noopener"><span>VMSA</span><span>-2025</span><span>-0003</span></a></li>
</ul>
<p> </p>]]></content:encoded>
						                            <category domain="https://www.virtualizationhowto.com/community/cybersecurity-forum/">Cybersecurity Forum</category>                        <dc:creator>Brandon Lee</dc:creator>
                        <guid isPermaLink="true">https://www.virtualizationhowto.com/community/cybersecurity-forum/vmsa-2025-0003-vmware-aria-operations-for-logs-and-vmware-aria-operations-vulnerability-patch-now/#post-1154</guid>
                    </item>
							        </channel>
        </rss>
		