CVE-2025-22215
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
08/01/2025
Last modified:
08/01/2025
Description
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM



