The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted S…
High CVSS 8.8
Summary
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://www.vmware.com/security/advisories/VMSA-2020-0016.html Vendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2020-0016.html Vendor Advisory
Timeline
- nvd_ingest NVD