CVE-2025-22221
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privi
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
MEDIUM · CVSS 5.2
EPSS 0.00244
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0