CVE-2024-22280: VMware Aria Automation

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.

Affected products

  • VMware Aria Automation: before 8.17.0 (fixed in 8.17.0)
  • VMware Cloud Foundation: from 4.0, up to and including 5.0

Published 2024-07-11. Last modified 2026-06-17.