This is a public Hot Fix that addresses the following issues:
This release resolves CVE-2025-22231. For more on this vulnerability and its impact on VMware products, see VMSA-2025-0006.
The following CVEs have been resolved :
VMware Aria Operations 8.18
This patch can be applied to any 8.18.x environment.
Note: Upgrading from older versions directly to this Patch is not supported. You must upgrade to 8.18.x before applying this Patch.
There are two different methods of updating to this patch. Both are described below.
Directly applying the patch to Aria Operations (Manual / Standalone) and through Aria Suite Lifecycle Manager (Updating through Aria Suite Lifecycle Manager).
Note: You will need to login to the portal first to allow download of the file using the direct links above.
Important: Take snapshots of each of the VMware Aria Operations nodes before applying the Patch by following How to take a Snapshot of VMware Aria Operations.
For a detailed step by step guide on how to apply a system patch through Aria Suite Lifecycle manager please review KB:
How to Apply a System Patch to VMware Aria Automation Using Aria Lifecycle Manager
https://knowledge.broadcom.com/external/article/389977