CVE-2024-38814

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
16/10/2024
Last modified:
21/10/2024

Description

An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A<br /> malicious authenticated user with non-administrator privileges may be <br /> able to enter specially crafted SQL queries and perform unauthorized <br /> remote code execution on the HCX manager. <br /> Updates are available to remediate this vulnerability in affected VMware products.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:vmware_hcx:*:*:*:*:*:*:*:* 4.8.0 (including) 4.8.2 (including)
cpe:2.3:a:vmware:vmware_hcx:*:*:*:*:*:*:*:* 4.9.0 (including) 4.9.1 (including)
cpe:2.3:a:vmware:vmware_hcx:4.10.0:*:*:*:*:*:*:*