Database/Control plane, storage & DevOps
VMware Aria Automation (SQL injection): An authenticated user injects SQL and performs unauthorized read/write
CVSS 8.5CVE-2024-22280Control plane, storage & DevOpscurated
Impact
An authenticated user injects SQL and performs unauthorized read/write against the Aria Automation database, which drives automated provisioning across the estate.
Who can reach it
Authenticated low-privilege Aria Automation user.
What to do
Apply the Broadcom fix per advisory 24598. Appliance patch and restart.
References
Related entries
- Juniper Security Director Policy Enforcer: unauthenticated attacker can replace vSRX images pushed to VMware NSXCVE-2025-11198 · Juniper Security Director Policy Enforcer (vSRX image upload)High
- VMware Aria Operations for Logs (credential disclosure): A View Only Admin reads the credentials of other VMwareCVE-2025-22218 · VMware Aria Operations for Logs (credential disclosure)High
- VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissionsCVE-2025-41250 · VMware vCenter (SMTP header injection via scheduled tasks)High
- AMD NBIO register lock bits - System Management Network access: NBIO registers that should be locked after boot areCVE-2025-61972 · AMD NBIO register lock bits - System Management Network accessHigh
- Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scoredCVE-2026-0207 · Pure Storage FlashBlade loggingHigh
- GitLab package registry: authenticated path traversal that can lead to remote code executionCVE-2026-10053 · GitLab CE/EE package registryHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.