- published 1/21/25 9:12 AM •
- updated 13 January 2025 •
- 3 Min Read
Security Updates - VMware Aria Automation
Alert Rating
Audience
Corporations, Government
On this page
Security Updates - VMware Aria Automation
Vulnerability Details:
- CVE-2025-22215
- CVSS v3 Base Score: 4.3
- Severity: Medium
- A server-side request forgery (SSRF) vulnerability exists in VMware Aria Automation. This SSRF vulnerability could allow a malicious actor with "Organization Member" access to enumerate internal services running on the host/network. This could potentially lead to unauthorized access to sensitive information or further exploitation of internal systems.
Affected Products and Versions:
- VMware Aria Automation versions 8.x
- VMware Cloud Foundation versions 5.x and 4.x
Fixed Versions:
- VMware Aria Automation 8.x: Upgrade to version 8.18.1 patch 1
- VMware Cloud Foundation 5.x and 4.x: Apply the patch referenced in KB 385294
Take Action
Protect yourself
Review the attached document and apply the necessary updates as outlined by the vendor. These updates are crucial for addressing the identified security vulnerability and ensuring that your system remains protected
GET INVOLVED
Make a Difference
Other Threats
20 January 2025
Critical Vulnerability in F5 Traffix SDC
A critical vulnerability has been discovered in F5 Traffix SDC, linked to Apache Tomcat, which could allow attackers to gain unauthorized access to compromised systems.
Protecting
Corporations, Government
17 January 2025
NVIDIA has released security updates to address multiple vulnerabilities in the NVIDIA Container Toolkit and NVIDIA GPU Operator.
Protecting
Corporations, Government
16 January 2025
Critical Vulnerability in FortiSwitch Devices
A critical vulnerability (CVE-2023-37936) has been discovered in multiple versions of Fortinet FortiSwitch devices. This vulnerability, classified as a use of hard-coded cryptographic key [CWE-321], allows a remote unauthenticated attacker in possession of the key to execute unauthorized code via crafted cryptographic request.
Protecting
Corporations, Government