CVE-2025-22215: VMware Aria Automation

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.

Affected products

  • VMware VMware Aria Automation: from 8, before 8.18.1 patch 1 (fixed in 8.18.1 patch 1)
  • VMware VMware Cloud Foundation VMware Aria Automation: from 5, before 8.18.1 patch 1 (fixed in 8.18.1 patch 1); from 4, before 8.18.1 patch 1 (fixed in 8.18.1 patch 1)

Published 2025-01-08. Last modified 2026-06-17.