PT-2024-19301 · Vmware · Vmware Aria Automation

Alexandre Lavoie

+1

·

Published

2024-07-10

·

Updated

2024-09-04

·

CVE-2024-22280

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions VMware Aria Automation versions 8.x
Description The issue is related to a lack of correct input validation, allowing for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorized read/write operations in the database.
Recommendations For VMware Aria Automation version 8.x, apply the available patches to address the SQL-injection vulnerability. As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-22280

Affected Products

Vmware Aria Automation