VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
2024-07-11T05:15:10.123
2025-03-14T19:15:44.857
Modified
CVSSv3.1: 8.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | aria_automation | < 8.17.0 | Yes |
Application | vmware | cloud_foundation | ≤ 5.0 | Yes |