1 results (0.001 seconds)

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged. VeloCloud Orchestrator, no aplica una comprobación de entrada correcta que permite una inyección SQL ciega. Un actor malicioso con acceso tenant a Velocloud Orchestrator podría introducir consultas SQL especialmente diseñadas y obtener datos que no son privilegiados • https://www.vmware.com/security/advisories/VMSA-2020-0016.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •