Multiple vulnerabilities in VMware Aria Operations and VMware Tools were privately reported to Broadcom. Patches are available to remediate these vulnerabilities in affected Broadcom products.
VMware Aria Operations updates address a local privilege escalation vulnerability (CVE-2025-22231)
Issue date:
2025-04-01
Updated on:
2025-04-01 (Initial Advisory)
CVE(s)
CVE-2025-22231
Impacted Products:
VMware Aria Operations
VMware Cloud Foundation
VMware Telco Cloud Platform
VMware Telco Cloud Infrastructure
Introduction:
A local privilege escalation vulnerability in VMware Aria Operations was responsibly reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.
Local Privilege escalation vulnerability (CVE-2025-22231)
Description:
VMware Aria Operations contains a local privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.
Known Attack Vectors:
A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations.
Resolution:
To remediate CVE-2025-22231 apply the patches listed in the ‘Fixed Version’ column of the ‘Response Matrix’ found below.
Workarounds:
None.
Additional Documentation:
None.
Acknowledgements:
VMware would like to thank thiscodecc of MoyunSec Vlab and Bing for reporting this issue to us.
VMware Aria Automation update addresses a server side request forgery vulnerability (CVE-2025-22215)
Issue date:
2025-01-07
Updated on:
2025-01-07
CVE(s)
CVE-2025022215
Impacted Products:
VMware Aria Automation
VMware Cloud Foundation
Introduction:
A server-side request forgery (SSRF) vulnerability in VMware Aria Automation was responsibly reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.
Descriptions:
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.3.
Known Attack Vectors:
A malicious actor with “Organization Member” access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
Resolution:
To remediate CVE-2025-22215 apply the patches listed in the ‘Fixed Version’ column of the ‘Response Matrix’ found below.
VMware has announced the official renaming of all products in our cloud management family to VMware Aria.
What is VMware Aria?
A unified management solution for cloud native applications and multi-cloud.
VMware Aria, a multi-cloud management portfolio that provides a set of end-to-end solutions for managing the cost, performance, configuration, and delivery of infrastructure and applications. Expressly designed for the operational challenges of cloud-native applications and public cloud environments, VMware Aria truly delivers a wholly new perspective on multi-cloud management.
The VMware Aria Product List
Previous Name
New Name
Automation
vRealize Automation / Cloud
VMware Aria Automation
VMware Cloud Assembly
VMware Aria Automation Assembler
VMware Service Broker
VMware Aria Automation Service Broker
VMware Code Stream
VMware Aria Automation Pipelines
VMware Cloud Templates
VMware Aria Automation Templates
vRealize Orchestrator
VMware Aria Automation Orchestrator
vRealize Automation SaltStack Config
VMware Aria Automation Config
vRealize Automation SaltStack SecOps
VMware Aria Automation for Secure Hosts
CloudHealth Secure State
VMware Aria Automation for Secure Clouds
Operations
vRealize Operations / Cloud
VMware Aria Operations
vRealize Log Insight / Cloud
VMware Aria Operations for Logs
vRealize Network Insight / Cloud
VMware Aria Operations for Networks
Tanzu Observability by Wavefront
VMware Aria Operations for Applications
vRealize True Visibility Suite
VMware Aria Operations for Integrations
Cost
CloudHealth
VMware Aria Cost powered by CloudHealth
Suites
vRealize Cloud Universal
VMware Aria Universal Suite
vRealize Suite
VMware Aria Suite
vCloud Suite
VMware vCloud Suite
CloudHealth by VMware Suite
Discontinued Name
CloudHealth Partner Platform
Discontinued Name – see Aria Cost powered by CloudHealth
Platform & Cross-Cloud Services
Project Ensemble
VMware Aria Hub
New
VMware Aria Graph
vRealize Migration Manager
VMware Aria Migration
vRealize Automation Cloud Guardrails
VMware Aria Guardrails
Project Ensemble Insights
VMware Aria Business Insights
Other
Skyline
VMware Skyline
vRealize Suite Lifecycle Manager
VMware Aria Suite Lifecycle
vRealize Cloud Subscription Manager
VMware Aria Hub Subscription
vRealize AI Cloud
Discontinued Name – functionality now part of Aria Hub
Reference:
Please see the links listed below for further information about VMware Aria and the portfolio products.