PT-2020-5372 · Vmware · Vmware Sd-Wan Orchestrator

Christopher Schneider

·

Published

2020-11-24

·

Updated

2020-12-07

·

CVE-2020-4003

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware SD-WAN Orchestrator versions 3.3.2 through 3.3.2 P3 VMware SD-WAN Orchestrator versions 3.4.x through 3.4.4 VMware SD-WAN Orchestrator versions 4.0.x through 4.0.1
Description The issue is related to the lack of protection against SQL query structure exploitation in the VMware SD-WAN Orchestrator platform. This can allow a remote attacker to gain unauthorized access to protected information. An authenticated SD-WAN Orchestrator user may inject code into SQL queries, potentially leading to information disclosure.
Recommendations For versions 3.3.2 through 3.3.2 P3, update to version 3.3.2 P3 or later. For versions 3.4.x through 3.4.4, update to version 3.4.4 or later. For versions 4.0.x through 4.0.1, update to version 4.0.1 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00286
CVE-2020-4003

Affected Products

Vmware Sd-Wan Orchestrator