CVE-2023-32569
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
10/05/2023
Last modified:
28/01/2025
Description
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the back-end database to create, read, update, or delete any sensitive data stored in the database.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:veritas:infoscale_operations_manager:*:*:*:*:*:*:*:* | 7.4.2.800 (excluding) | |
| cpe:2.3:a:veritas:infoscale_operations_manager:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.0.410 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



