Database/Control plane, storage & DevOps
VMware Aria Automation (DOM-based XSS, token theft): A crafted URL steals the access token of a logged-in Aria
CVSS 8.2CVE-2025-22249Control plane, storage & DevOpscurated
Impact
A crafted URL steals the access token of a logged-in Aria Automation user, letting the attacker act as that user against the automation platform.
Who can reach it
Unauthenticated attacker who can get an operator to click a crafted link.
What to do
Apply the Broadcom fix per advisory 25711.
References
Related entries
- OpenShift Hive / MCE / ACM (vCenter credential exposure): vCenter credentials are written into the ClusterProvisionCVE-2025-2241 · OpenShift Hive / MCE / ACM (vCenter credential exposure)High
- Jenkins (Git Parameter plugin): Git parameter value is not validated against the offered choicesCVE-2025-53652 · Jenkins (Git Parameter plugin)High
- Foreman: command injection in the errors:fetch_log rake task escalates a scoped sudo grant to full code executionCVE-2026-12540 · Foreman / Red Hat Satellite (foreman-rake errors:fetch_log task)High
- Foreman / Red Hat Satellite: shell injection via foreman-rake db:dump and db:import_dump pathsCVE-2026-12541 · Foreman / Red Hat Satellite (foreman-rake db:dump and db:import_dump tasks)High
- IBM AIX and PowerVM VIOS: improper authentication allows remote access to NFS exportsCVE-2026-16686 · IBM AIX / PowerVM VIOS NFS server (export authentication)High
- Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated APICVE-2026-5944 · Cisco Intersight Device Connector for Nutanix Prism CentralHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.