CVE-2020-3973: SQL Injection
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3973?
CVE-2020-3973 has been rated as critical due to the potential for blind SQL injection leading to unauthorized data access.
How do I fix CVE-2020-3973?
To remediate CVE-2020-3973, upgrade VMware VeloCloud Orchestrator to version 3.4.0 or later.
Who is affected by CVE-2020-3973?
CVE-2020-3973 affects users with tenant access to VMware VeloCloud Orchestrator versions 3.1.1 to 3.3.2.
What type of attack does CVE-2020-3973 enable?
CVE-2020-3973 enables blind SQL injection attacks that can expose sensitive data.
Is CVE-2020-3973 specific to a particular operating system?
CVE-2020-3973 affects VMware VeloCloud Orchestrator and is independent of the underlying Linux operating system.