- Security updates addressing vulnerabilities in VMware products have been released.
- The affected products are VMware Aria Automation 8.18.x, VMware Cloud Foundation 5.x and 4.x, and VMware Telco Cloud Platform 5.x.
- The resolved vulnerability is CVE-2025-22249, a DOM-based cross-site scripting (XSS) vulnerability in VMware Aria Automation that exploits the DOM of a web page.
- A Vulnerability Patch for this vulnerability is provided through the latest update.
- Users are advised to update VMware Aria Automation to version 8.18.1 Patch 2.
- For VMware Cloud Foundation, users should refer to the reference site to apply the patch.
- For VMware Telco Cloud Platform, an update to version 8.18.1 Patch 2 has been recommended.
- VMSA-2025-0008 and VMware Aria Automation 8.18.1 Cumulative Update #2 are provided as reference materials.