First published: Wed May 10 2023(Updated: )
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage this to read sensitive data stored on the servers, modify data or server configuration, and delete data or application configuration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas InfoScale Operations Manager | <7.4.2.800 | |
Veritas InfoScale Operations Manager | >=8.0.0<8.0.410 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-32568 is high with a severity value of 7.2.
Veritas InfoScale Operations Manager is a software used for managing and monitoring Veritas InfoScale storage solutions.
Veritas InfoScale Operations Manager versions before 7.4.2.800 and 8.x before 8.0.410 are affected by CVE-2023-32568.
The vulnerability category of CVE-2023-32568 is CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
To fix CVE-2023-32568, update Veritas InfoScale Operations Manager to version 7.4.2.800 or later, or version 8.0.410 or later.