CVE-2023-32569

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
10/05/2023
Last modified:
28/01/2025

Description

An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the back-end database to create, read, update, or delete any sensitive data stored in the database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:veritas:infoscale_operations_manager:*:*:*:*:*:*:*:* 7.4.2.800 (excluding)
cpe:2.3:a:veritas:infoscale_operations_manager:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.410 (excluding)