9
CVE-2026-22720
- EPSS 0.08%
- Veröffentlicht 25.02.2026 19:33:14
- Zuletzt bearbeitet 04.03.2026 15:55:32
- Quelle security@vmware.com
- CVE-Watchlists
- Unerledigt
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Aria Operations Version >= 8.0 < 8.18.6
VMware ≫ Cloud Foundation Version >= 4.0 < 5.2.3
VMware ≫ Cloud Foundation Version >= 9.0 < 9.0.2.0
VMware ≫ Telco Cloud Infrastructure Version >= 2.2 <= 3.0
VMware ≫ Telco Cloud Platform Version >= 4.0 <= 5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.235 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
| security@vmware.com | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.