First published: Wed May 10 2023(Updated: )
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the back-end database to create, read, update, or delete any sensitive data stored in the database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas InfoScale Operations Manager | <7.4.2.800 | |
Veritas InfoScale Operations Manager | >=8.0.0<8.0.410 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32569 is a vulnerability in Veritas InfoScale Operations Manager (VIOM) that allows SQL injection attacks.
The severity of CVE-2023-32569 is critical (9.8).
Veritas InfoScale Operations Manager versions before 7.4.2.800 and 8.x before 8.0.410 are affected by CVE-2023-32569.
To exploit CVE-2023-32569, an attacker must have admin credentials and can submit arbitrary SQL commands through the InfoScale VIOM web application.
Yes, a fix is available for CVE-2023-32569. Update Veritas InfoScale Operations Manager to version 7.4.2.800 or later, or version 8.0.410 or later.