VMware, a leader in virtualization, issued an urgent advisory on Tuesday regarding a critical Blind SQL Injection vulnerability in its Avi Load Balancer . The company warns that the flaw could be exploited by attackers, allowing them to gain extensive access to its database.
See also: New Akira Linux Ransomware Attacks VMware ESXi Servers

The vulnerability, which is tracked as CVE-2025-22217, carries a CVSS severity rating of 8.6/10.
VMware described the security flaw as an unverified Blind SQL Injection and urged enterprise administrators to urgently apply available patches, as there are no workarounds before the patch.
A bulletin from VMware warned that "a malicious user with network access may be able to use specially crafted SQL queries to gain access to the database."
VMware Avi Load has established itself as one of the leading solutions for distributing and managing inbound traffic across multiple servers, ensuring consistent and reliable performance for applications in both the cloud and on-premises. In addition to load balancing, it offers advanced security for web applications and supports container ingress, meeting the needs of applications in cloud and datacenter environments.
See also: Ransomware gang uses SSH tunnels to covertly access VMware ESXi
The product is designed to work with traditional VM-based applications and container microservices.

VMware advises customers running Avi Load Balancer versions 30.1.1, 30.1.2, 30.2.1 , and 30.2.2 to quickly install available patches to protect against the SQL Injection flaw. Administrators to upgrade to at least version 30.1.2 or later before applying the patch in cases where older versions exist.
There are currently no known workarounds, making updating the only effective protection.
The vulnerability was privately reported to VMware. The company credits researchers Daniel Kukuczka and Mateusz Darda with the discovery.
See also: VMware patches serious vulnerabilities in Aria Operations
SQL Injection is a security vulnerability that occurs when a malicious user inserts malicious SQL code into an input field with the intent of performing unwanted actions on the database. This attack allows third parties to violate the integrity of the database, gain access to sensitive information, or even delete data. It typically exploits the lack of proper input validation and can have devastating consequences for a system or business.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
