VMware released security updates to address five vulnerabilities in its Aria Operations product. Aria Operations (formerly known as VMware vRealize Operations) is a comprehensive cloud management and operations platform developed by VMware. It is designed to provide IT administrators and cloud professionals with tools to optimize, manage, and troubleshoot their hybrid and multi-cloud environments.
The virtualization giant addressed the following vulnerabilities:
Here are the details from VMware’s VMSA-2024-0022 bulletin:
Below is the response matrix published by VMware:
Product | Version | Running On | CVE | CVSSv3 | Severity | Fixed versions | Workaround | Additional Documents |
VMware Aria Operations | 8.x | Any | CVE-2024-38830, CVE-2024-38831, CVE-2024-38832,CVE-2024-38833, CVE-2024-38834 | 7.8 , 7.8, 7.1, 6.8, 6.5 | Important | 8.18.2 | None | None |
VMware Cloud Foundation (VMware Aria Operations) | 5.x | Any | CVE-2024-38830, CVE-2024-38831, CVE-2024-38832,CVE-2024-38833, CVE-2024-38834 | 7.8 , 7.8, 7.1, 6.8, 6.5 | Important | 8.18.2 | None | None |
VMware Cloud Foundation (VMware Aria Operations) | 4.x | Any | CVE-2024-38830, CVE-2024-38831, CVE-2024-38832,CVE-2024-38833, CVE-2024-38834 | 7.8 , 7.8, 7.1, 6.8, 6.5 | Important | 8.18.2 | None | None |
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, VMWARE)