First published: Wed May 09 2018(Updated: )
SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injection.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
HP Network Operations Management Ultimate | =2017.07 | |
HP Network Operations Management Ultimate | =2017.11 | |
HP Network Operations Management Ultimate | =2018.02 | |
HP Network Automation | =10.00 | |
HP Network Automation | =10.10 | |
HP Network Automation | =10.11 | |
HP Network Automation | =10.20 | |
HP Network Automation | =10.30 | |
HP Network Automation | =10.40 | |
HP Network Automation | =10.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6493 is considered a high severity vulnerability due to the potential for remote SQL injection.
To fix CVE-2018-6493, it is recommended to update affected HP Network Operations Management Ultimate and HP Network Automation versions to the latest patched versions.
CVE-2018-6493 affects HP Network Operations Management Ultimate versions 2017.07, 2017.11, and 2018.02, as well as HP Network Automation versions 10.00 through 10.50.
Yes, CVE-2018-6493 can be remotely exploited, allowing attackers to execute SQL injection attacks on the affected systems.
Exploitation of CVE-2018-6493 can lead to unauthorized access to the database and exposure of sensitive data.