VMware good2know [CW14]

Newsletter

Product Releases

ProductVersionRelease DateDownloadDocumentation
Aria Operations8.18 HF504/01DownloadDocumentation

VMware Security Advisory

VMSA-2025-0005 [IMPORTANT][CVSSv3: 7.8]

Products:

  • Aria Operations

CVE(s):

  • VMware Aria Operations updates address a local privilege escalation vulnerability (CVE-2025-22231)

Description: 

  • VMware Aria Operations contains a local privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations. To remediate CVE-2025-22231 apply the patches listed in the ‚Fixed Version‘ column of the ‚Response Matrix‘ found below. VMware would like to thank thiscodecc of MoyunSec Vlab and Bing for reporting this issue to us.
ProductVersionCVEFixedWorkaround
Aria Operations8.xCVE-2025-222318.18 HF 5none
VCF5.x / 4.xCVE-2025-22231KB articlenone
Telco Cloud Plat.5.x / 4.x / 3.xCVE-2025-222318.18 HF 5none
Telco CLoud Infra.3.x / 2.xCVE-2025-222318.18 HF 5none

Product Lifecycle

ProductVersionEOL
VMware NSX3.2.507. Apr 25
VMware Bare Metal Automation for VMware Telco Cloud Platform3.018. Apr 25
VMware Cloud Provider Lifecycle Manager1.518. Apr 25
VMware Data Services Manager2.1.023. Apr 25
VMware Aria Operations for Networks6.10.027. Apr 25
VMware Aria Operations for Networks6.11.027. Apr 25
vSphere Bitfusion4.5.205. May 25
vSphere Bitfusion4.5.305. May 25
VMware Tools11.1.007. May 25
VMware Tools11.1.107. May 25
VMware Tools11.1.507. May 25
VMware Aria Automation8.17.009. May 25
VMware Aria Automation Orchestrator8.17.014. May 25
VMware Data Services Manager2.1.120. May 25
TKr 1.28.7 for vSphere 8.x1.28.728. May 25
TKr 1.28.8 for vSphere 8.x1.28.828. May 25
VMware Cloud Foundation4.531. May 25
VMware Cloud Foundation4.5.131. May 25
VMware Cloud Director Availability4.615. Jun 25
VMware Cloud Director Availability4.6.115. Jun 25
VMware Cloud Director Availability4.715. Jun 25
VMware Cloud Director Availability4.7.115. Jun 25
VMware Data Services Manager2.1.224. Jun 25
Uhana by VMware0.52.330. Jun 25
Uhana by VMware0.52.430. Jun 25
Uhana by VMware0.52.530. Jun 25
VMware vCloud Usage Meter4.830. Jun 25

KB Article

SubjectID
Error: Host <UUID> is not added to VDS value: <value> . (Error code: 9548)393260
NVMEOver TCP session to the storage lost after a reboot of the esxi hosts configured with Hostprofile393229
Rubrik VM backup failing with NFC_COMPRESSION_ERROR393216
Unable to update vsan HCL DB manually or online393204
Delete Snapshot list of Aria Automation Day 2 action is showing Snapshots that no longer exist393142
Cannot remove a Disk Group from the vSAN Cluster using vSphere UI393099
„Could not initialize plugin ‚libnvidia-vgx.so‘ for vGPU ‚profile_name‘ Failed to start the virtual machine. Module DevicePowerOn power on failed.“ error when powering on a VM with vGPU device393089
Appliance node not accepting new root password393065
Virtual Machines are either frozen or have turned invalid393060
After ESXi upgrade, a disk group with deduplication remains in an unhealthy state.392966
Offline bundle utility fails with the error: „Unable to create token after 8 retries“392946
„Password Expiry“ Alarm Not Triggered for Edge Nodes with Expired Root Passwords392915
Unable to configure NSX on nodes which were rebuilt in the cluster : Error Code 100392879
Cannot unmount volume ########## because One or more virtual machines are still registered on it.392867
Skyline adapter stops collecting and enters an error state392739
vSAN cluster showing 0 usage392730
Error: „PCI passthru device caused IOMMU fault“ when VM Powers Off Unexpectedly392714
Unable to Login to ESXi Using Domain Credentials, fails with the Error „Connection to ESXi Host Timed Out“392710
VMware Aria Orchestrator is crashing with error „java.lang.OutOfMemoryError: GC overhead limit exceeded“392695
vSAN Stretched Cluster Witness Appliance reports Network partition in vSAN Skyline Health check. Cannot add newly deployed Witness.392681
Can a VM or vmdk be recovered when VMFS metadata is overwritten?392614
After the power outage the vsan datastore not available392542
VIDM fails remediation LCMVIDM74066392519
Increasing the Width of a Data Grid in a Custom Form Using CSS392438

Podcast | Webinar | Blog Posts

Over 375 Reasons to Update VCF & Aria Operations
Architect’s Edge Live
04/29/25
Webinar
Unlocking the Latest Features in Aria Operations & VMware VCFIt’s time to move beyond just updating your systems — let’s talk about what you can actually do with those updates.With over 375 new features and updates since September, the possibilities are endless, but many of you may not realize what’s available or how to fully leverage it.
Join us for Architect’s Edge Live on Tuesday, April 29, 2025, at 11 AM PST—a casual, interactive coffee talk where we’ll break down these updates, explore what they can do for you, and help you fully maximize your VMware environment. This session is all about real conversations, real insights, and real customers—and it’s not just for those considering an update, but also for those already up-to-date.
Here’s what you’ll get from our panel of vExpert veterans—many of whom are customers themselves:
☕ What’s new: Over 375 updates and features you might not even know about🔧 Unlocking hidden capabilities: Never-before-seen features you can start using today💡 How to fully leverage your updates: Tips and tricks and LIVE DEMOS for making the most of the latest advancements❓ Open Q&A: Ask the experts what’s working, what’s not, and get advice on your VMware environment
Speaker:
Christopher Kusek – Principal Cloud Architect, VCF Division

Aria Operations 8.18 HF5
brockpeterson.com/
Blogpost
Aria Operations 8.18 HF5 just dropped this morning, fixing a few bugs and addressing several VMSAs/CVEs, go get it here!  You can apply it locally via the admin UI or via the Aria Suite Lifecycle Manager.  In this blog, I’ll apply it locally.

VCP-VCF Administrator Exam Study Group
VMware {code}
Podcast
Welcome to the VCP-VCF Administrator Exam Study Group playlist! This community-driven series is brought to you by the VMware {code} Community and {code} Coaches, designed to help you successfully prepare for the VMware Cloud Foundation (VCF) Administrator certification exam.This is a community-led initiative with no formal classes, just a collaborative effort to share knowledge and support each other’s success. Note that this series is intended to complement, not replace, the official Broadcom training classes found on the Broadcom Learning site.


Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert