CVE-2023-32569: SQL Injection
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the back-end database to create, read, update, or delete any sensitive data stored in the database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32569?
CVE-2023-32569 is a vulnerability in Veritas InfoScale Operations Manager (VIOM) that allows SQL injection attacks.
What is the severity of CVE-2023-32569?
The severity of CVE-2023-32569 is critical (9.8).
Which versions of Veritas InfoScale Operations Manager are affected by CVE-2023-32569?
Veritas InfoScale Operations Manager versions before 7.4.2.800 and 8.x before 8.0.410 are affected by CVE-2023-32569.
How can an attacker exploit CVE-2023-32569?
To exploit CVE-2023-32569, an attacker must have admin credentials and can submit arbitrary SQL commands through the InfoScale VIOM web application.
Is there a fix available for CVE-2023-32569?
Yes, a fix is available for CVE-2023-32569. Update Veritas InfoScale Operations Manager to version 7.4.2.800 or later, or version 8.0.410 or later.