CVE Database
/

CVE-2020-3973

Back to search

CVE-2020-3973

Published: Jul 8, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

VendorProductVersions

n/a

VMware SD-WAN by VeloCloud

affected
VMware SD-WAN by VeloCloud 3.2.x, 3.3.x prior to 3.3.2 p2, 3.4.x prior to 3.4.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now