CVE-2023-32568: OS Command Injection
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage this to read sensitive data stored on the servers, modify data or server configuration, and delete data or application configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32568?
The severity of CVE-2023-32568 is high with a severity value of 7.2.
What is Veritas InfoScale Operations Manager?
Veritas InfoScale Operations Manager is a software used for managing and monitoring Veritas InfoScale storage solutions.
What is the affected version range of Veritas InfoScale Operations Manager for CVE-2023-32568?
Veritas InfoScale Operations Manager versions before 7.4.2.800 and 8.x before 8.0.410 are affected by CVE-2023-32568.
What is the vulnerability category of CVE-2023-32568?
The vulnerability category of CVE-2023-32568 is CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
How can I fix CVE-2023-32568?
To fix CVE-2023-32568, update Veritas InfoScale Operations Manager to version 7.4.2.800 or later, or version 8.0.410 or later.