Database/Control plane, storage & DevOps
VMware Aria Automation (DOM-based XSS, token theft): A crafted URL steals the access token of a logged-in Aria
CVE-2025-22249Control plane, storage & DevOpscurated
Impact
A crafted URL steals the access token of a logged-in Aria Automation user, letting the attacker act as that user against the automation platform.
Who can reach it
Unauthenticated attacker who can get an operator to click a crafted link.
What to do
Apply the Broadcom fix per advisory 25711.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.