CVE-2025-22215: VMware Aria Automation
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
Affected products
- VMware VMware Aria Automation: from 8, before 8.18.1 patch 1 (fixed in 8.18.1 patch 1)
- VMware VMware Cloud Foundation VMware Aria Automation: from 5, before 8.18.1 patch 1 (fixed in 8.18.1 patch 1); from 4, before 8.18.1 patch 1 (fixed in 8.18.1 patch 1)
Published 2025-01-08. Last modified 2026-06-17.