CVE-2024-22280: VMware Aria Automation
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
Affected products
- VMware Aria Automation: before 8.17.0 (fixed in 8.17.0)
- VMware Cloud Foundation: from 4.0, up to and including 5.0
Published 2024-07-11. Last modified 2026-06-17.