CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 3Aria Automation Cloud FoundationTelco Cloud PlatformJun 17, 2026 May 13, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking...Show more |
1Vmware 2Aria Automation Cloud FoundationJun 17, 2026 Jul 11, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write...Show more |
1Vmware 2Aria Automation Cloud FoundationJun 17, 2026 Jan 16, 2024 N/A· v4 8.3 HIGH· v3 N/A· v2 Aria Automation contains a Missing Access Control vulnerability.
An authenticated malicious actor may
exploit this vulnerability leading to unauthorized access to remote
organizations and workflows.
|