CVE-2024-22280
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
11/07/2024
Last modified:
14/03/2025
Description
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
Impact
Base Score 3.x
8.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:aria_automation:*:*:*:*:*:*:*:* | 8.17.0 (excluding) | |
| cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | 4.0 (including) | 5.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



