An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager.  Updates are available to remediate this vulnerability in affected VMware products.
History

Mon, 21 Oct 2024 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:vmware:vmware_hcx:4.10.0:*:*:*:*:*:*:*

Wed, 16 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware vmware Hcx
CPEs cpe:2.3:a:vmware:vmware_hcx:*:*:*:*:*:*:*:*
Vendors & Products Vmware
Vmware vmware Hcx
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Description An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager.  Updates are available to remediate this vulnerability in affected VMware products.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2024-10-16T16:59:20.174Z

Updated: 2024-10-16T17:53:24.283Z

Reserved: 2024-06-19T22:31:57.187Z

Link: CVE-2024-38814

cve-icon Vulnrichment

Updated: 2024-10-16T17:51:07.505Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T17:15:16.237

Modified: 2024-10-21T18:20:53.267

Link: CVE-2024-38814

cve-icon Redhat

No data.