First published: Tue Nov 07 2023(Updated: )
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam ONE | =11.0.0.1379 | |
Veeam ONE | =11.0.1.1880 | |
Veeam ONE | =12.0.0.2498 | |
Veeam ONE | =12.0.1.2591 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38547 is a vulnerability in Veeam ONE that allows an unauthenticated user to gain information about the SQL server connection used to access its configuration database, potentially leading to remote code execution on the SQL server.
The severity of CVE-2023-38547 is critical, with a severity value of 9.9.
Veeam ONE versions 11.0.0.1379, 11.0.1.1880, 12.0.0.2498, and 12.0.1.2591 are affected by CVE-2023-38547.
An unauthenticated user can gain information about the SQL server connection and potentially execute remote code on the SQL server.
To fix the CVE-2023-38547 vulnerability, update Veeam ONE to a version that is not affected by the vulnerability. Refer to the Veeam website for the necessary patches or updates.