VMware Aria Operations for Logs Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing information disclosure has been identified in VMware Aria Operations for Logs. This issue arises from a flaw that enables a malicious actor with View Only Admin permissions to potentially access the credentials of a VMware product integrated with Aria Operations for Logs. VMware has assigned this vulnerability a severity rating of Important, with a maximum CVSSv3 base score of 8.5.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive credentials, which may be misused to compromise integrated VMware products.

Remediation

Users can upgrade to VMware Aria Operations for Logs version 8.18.3 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.