VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.
VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.
| Vendor | Product | Versions |
|---|---|---|
| VMware | VMware Aria Operations | 8.18.x |
| VMware | VMware Cloud Foundation | 5.x, 4.x |
| VMware | VMware Telco Cloud Platform | 5.x, 4.x |
| VMware | VMware Telco Cloud Infrastructure | 3.x, 2.x |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice: