Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2025-22215

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
0
Attacker Value
Unknown

CVE-2024-22280

Disclosure Date: July 11, 2024 (last updated July 13, 2024)
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
Attacker Value
Unknown

CVE-2023-34063

Disclosure Date: January 16, 2024 (last updated January 26, 2024)
Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.