Home
HIGH: 8.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NDefault status
unaffected
8.x (8.17.0) before 8.17.0
affected
Description
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
Product status
8.x (8.17.0) before 8.17.0
References
support.broadcom.com/...l/content/SecurityAdvisories/0/24598
support.broadcom.com/...l/content/SecurityAdvisories/0/24598
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.