Remediation for PostgreSQL vulnerabilities in VMware Aria Suite Lifecycle 8.18.0
search cancel

Remediation for PostgreSQL vulnerabilities in VMware Aria Suite Lifecycle 8.18.0

book

Article ID: 442979

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Security scans identify multiple vulnerabilities in the PostgreSQL component of VMware Aria Suite Lifecycle 8.18.0. The scanner reports the following details:

  • Path/opt/vmware/vpostgres/14/bin/postgres
  • Installed Version: 14.20
  • Fixed Version: 14.23

Affected CVEs: CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638

Environment

VMware Aria Suite Lifecycle 8.18.0

Cause

The PostgreSQL 14.20 version bundled with VMware Aria Suite Lifecycle 8.18.0 is susceptible to multiple vulnerabilities identified by the CVEs listed above.

Resolution

Engineering has confirmed that all reported CVEs are scheduled to be addressed in the next major release of the product.

  • Target Version: VMware Aria Suite Lifecycle 8.18.0 Patch 9 (or next version)

There is currently no interim patch available for these specific PostgreSQL vulnerabilities. Customers are advised to monitor the official  for the release of the updated version.