VMware good2know [CW05]

Newsletter

Release Notes

ProductVersionRelease DateDownloadRelease Notes
Aria Operations for Logs8.18.301/28DownloadRelease Notes
Aria Operations8.18.301/30DownloadRelease Notes
Aria Suite Lifecycle Manager8.18 PSPack501/31DownloadRelease Notes
#Release Notes

VMSA-2025-0003[HIGH] [CSSv3 8.6]

CVE(s)

  • VMware Aria Operations for Logs information disclosure vulnerability (CVE-2025-22218) 
  • VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219) 
  • VMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220) 
  • VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22221)
  • VMware Aria Operations information disclosure vulnerability (CVE-2025-22222)

Description

  • VMware would like to thank Maxime Escourbiac, Michelin CERT, Yassine Bengana, Abicom from Michelin CERT and Quentin Ebel, Abicom from Michelin CERT for reporting this issue to us.

Response Matrix

ProductCVEFixed VersionWorkaround
Aria Operations for LogsCVE-2025-22218, CVE-2025-22219, 
CVE-2025-22220, CVE-2025-22221
8.18.3None
Aria OperationsCVE-2025-222228.18.3None
VCFCVE-2025-22218, CVE-2025-22219, 
CVE-2025-22220, CVE-2025-22221, CVE-2025-22222
KB92148
None
#VMSA-2025-0003

KB Articles

Subject

KB Article

Broadcom Service Status Page – Microsoft Teams Retiring Webhook-based Connectors387207

Archive All Active Alerts in Aria Operations for Networks

387204

In Aria Operations for Logs, the vSphere integration menu shows no data when connecting via a reverse proxy.

387144

A general system error occurred: Too many outstanding operations

387133

Objects in Operations do not have any historical data after recent outage

387126

Error „Operation failed Failed to start the virtual machine. Cannot open the disk“ while powering on a virtual machine

386984

Ping over an NSX L2 Bridge fails

386954

Devices from an ALUA capable storage array claimed by VMW_SATP_DEFAULT_AA

386937

Generating database dump / Backing up Embedded postgres database on Aria Suite Lifecycle 8.x

386932

Incorrect Target VM Folder Names Created by HCX Bulk Migration

386914

„Audio Passthrough Not Working on Windows 10 VMs“

386903

HCX Manager Snapshots in VMC Environment

386884

HMS Service Failure and Site Pairing Issues After VRMS 8.x Upgrade Due to Disabled Embedded HBR Server

386839

Can’t take a Quiesce Snapshot because VMware Snapshot Provider Service is missing on Windows

386801

Single Node Cluster redirecting to IP address after vIDM integration

386779

An expired or expiring client auth certificate is present in the NSX inventory

386744

Broadcom Service Status Page – Microsoft Teams Retiring Webhook-based Connectors

387207

#KB-Article

OnSite Events

EventDate
VMUG User/con Dutch03/12
VMUG User/con Philadelphia03/25
VMUG Connect04/23-25
VMUG User/con German05/08
Carolina User/con05/08
Toronto User/con05/19
Denver User/con05/29
Belgian User/con06/05
Swedish User/con09/23
Explore 2025 – Las Vegas08/25

Podcast | Webinar | Blog Posts

Passwordless login to vCenter Server or VMware Cloud Foundation (VCF) using Apple Face ID or Yubico YubiKey (BlogPost)
After spending some time playing with a couple of self-hosted Identity Providers solutions like Authentik and Keycloak for use with vCenter Server Identity Federation, I was curious about their Multi-Factor Authentication (MFA) support. Specifically, I was interested in their WebAuthn capabilities, which should allow me to use the popular Yubico YubiKey for passwordless authentication into my VMware environment. 😊

What’s New for 2025? Level Up with VMware {code}! (VMware Blods)
Announcements | What’s New for 2025? VMware {code} Community Calls: A Space to Learn, Share, and Connect; plus Certification Study Groups. – Find out the details here and get involved!

VMware vDefend Threat Protection: Security and Resiliency (BlogPost)
In an era where cyber threats are evolving rapidly, businesses must adopt cutting-edge security solutions to safeguard their infrastructure. VMware vDefend is a next-generation threat protection system designed to enhance security and resiliency across virtual environments. This article explores the latest updates, key functionalities, and how vDefend contributes to a more resilient IT ecosystem.


Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert