First published: Wed Jul 08 2020(Updated: )
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware VeloCloud Orchestrator | >=3.1.1<3.3.2 | |
VMware VeloCloud Orchestrator | =3.3.2 | |
VMware VeloCloud Orchestrator | =3.4.0 | |
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.