CVE-2023-38547: Infoleak
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-38547?
CVE-2023-38547 is a vulnerability in Veeam ONE that allows an unauthenticated user to gain information about the SQL server connection used to access its configuration database, potentially leading to remote code execution on the SQL server.
What is the severity of CVE-2023-38547?
The severity of CVE-2023-38547 is critical, with a severity value of 9.9.
Which versions of Veeam ONE are affected by CVE-2023-38547?
Veeam ONE versions 11.0.0.1379, 11.0.1.1880, 12.0.0.2498, and 12.0.1.2591 are affected by CVE-2023-38547.
What can an unauthenticated user do with CVE-2023-38547?
An unauthenticated user can gain information about the SQL server connection and potentially execute remote code on the SQL server.
How can I fix the CVE-2023-38547 vulnerability?
To fix the CVE-2023-38547 vulnerability, update Veeam ONE to a version that is not affected by the vulnerability. Refer to the Veeam website for the necessary patches or updates.