CVE-2020-3973
08.07.2020, 14:15
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.
Vendor | Product | Version |
---|---|---|
vmware | velocloud_orchestrator | 3.1.1 ≤ 𝑥 < 3.3.2 |
vmware | velocloud_orchestrator | 3.3.2 |
vmware | velocloud_orchestrator | 3.4.0 |
𝑥
= Vulnerable software versions