6.5

CVE-2020-4003

VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WAN Orchestrator user may inject code into SQL queries which may lead to information disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Sd-wan Orchestrator Version >= 3.4.0 < 3.4.4
VMware ≫ Sd-wan Orchestrator Version >= 4.0.0 < 4.0.1
VMware ≫ Sd-wan Orchestrator Version 3.3.2 Update -
VMware ≫ Sd-wan Orchestrator Version 3.3.2 Update p1
VMware ≫ Sd-wan Orchestrator Version 3.3.2 Update p2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.15% 0.645
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

http://www.vmware.com/security/advisories/VMSA-2020-0025.html
Vendor Advisory