malicious authenticated user with non-administrator privileges may be
able to enter specially crafted SQL queries and perform unauthorized
remote code execution on the HCX manager.
Updates are available to remediate this vulnerability in affected VMware products.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37637 | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager. Updates are available to remediate this vulnerability in affected VMware products. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Oct 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vmware:vmware_hcx:4.10.0:*:*:*:*:*:*:* |
Wed, 16 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware vmware Hcx |
|
| CPEs | cpe:2.3:a:vmware:vmware_hcx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vmware
Vmware vmware Hcx |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager. Updates are available to remediate this vulnerability in affected VMware products. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-10-16T17:53:24.283Z
Reserved: 2024-06-19T22:31:57.187Z
Link: CVE-2024-38814
Updated: 2024-10-16T17:51:07.505Z
Status : Analyzed
Published: 2024-10-16T17:15:16.237
Modified: 2024-10-21T18:20:53.267
Link: CVE-2024-38814
No data.
OpenCVE Enrichment
No data.
EUVD