CVE-2024-22280

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
11/07/2024
Last modified:
14/03/2025

Description

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:aria_automation:*:*:*:*:*:*:*:* 8.17.0 (excluding)
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* 4.0 (including) 5.0 (including)