GPU VulnDB

Database/Control plane, storage & DevOps

VMware Aria Operations for Logs (credential disclosure): A View Only Admin reads the credentials of other VMware

CVE-2025-22218Control plane, storage & DevOpscurated

Impact

A View Only Admin reads the credentials of other VMware products integrated with Aria Operations for Logs - so the lowest-privilege admin role yields credentials for vCenter and friends.

Who can reach it

Authenticated View Only Admin on Aria Operations for Logs.

What to do

Apply the Broadcom fix per advisory 25329, then rotate the integration credentials that were stored - anyone holding that role could already have read them.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.