Description
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2676 | VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user. |
References
History
Wed, 14 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware aria Operations For Logs Vmware cloud Foundation |
|
| CPEs | cpe:2.3:a:vmware:aria_operations_for_logs:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vmware
Vmware aria Operations For Logs Vmware cloud Foundation |
Thu, 06 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
ssvc
|
Thu, 30 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user. | |
| Title | VMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220) | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-02-26T19:08:53.986Z
Reserved: 2025-01-02T04:29:30.444Z
Link: CVE-2025-22220
Updated: 2025-02-06T14:05:56.664Z
Status : Analyzed
Published: 2025-01-30T16:15:31.143
Modified: 2025-05-14T16:46:59.413
Link: CVE-2025-22220
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD