Database/Control plane, storage & DevOps
VMware Aria Automation (SQL injection): An authenticated user injects SQL and performs unauthorized read/write
CVE-2024-22280Control plane, storage & DevOpscurated
Impact
An authenticated user injects SQL and performs unauthorized read/write against the Aria Automation database, which drives automated provisioning across the estate.
Who can reach it
Authenticated low-privilege Aria Automation user.
What to do
Apply the Broadcom fix per advisory 24598. Appliance patch and restart.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.