CVE-2024-22280
11.07.2024, 05:15
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product.An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
Vendor | Product | Version |
---|---|---|
vmware | aria_automation | 𝑥 < 8.17.0 |
vmware | cloud_foundation | 4.0 ≤ 𝑥 ≤ 5.0 |
𝑥
= Vulnerable software versions