PT-2023-8939 · Veritas · Veritas Infoscale Operations Manager

Published

2023-05-02

·

Updated

2023-05-16

·

CVE-2023-32568

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Veritas InfoScale Operations Manager versions prior to 7.4.2.800 Veritas InfoScale Operations Manager versions 8.x prior to 8.0.410
Description The issue arises from the VIOM web application's failure to validate user-supplied data, which is then appended to OS commands and internal binaries. This allows an attacker with root or administrator privileges to read sensitive data, modify server configurations, or delete data and application configurations. The vulnerability can be exploited by a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 7.4.2.800, update to version 7.4.2.800 or later. For versions 8.x prior to 8.0.410, update to version 8.0.410 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-02737
CVE-2023-32568

Affected Products

Veritas Infoscale Operations Manager