PT-2025-4396 · Vmware · Vmware Aria Operations For Logs

Maxime Escourbiac

+2

·

Published

2025-01-30

·

Updated

2025-05-14

·

CVE-2025-22220

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions VMware Aria Operations for Logs (affected versions not specified)
Description The issue is related to insecure privilege management in VMware Aria Operations for Logs, allowing a malicious actor with non-administrative privileges and network access to the Aria Operations for Logs API to perform certain operations in the context of an admin user. This is a result of a privilege escalation issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-01354
CVE-2025-22220

Affected Products

Vmware Aria Operations For Logs