An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A
malicious authenticated user with non-administrator privileges may be
able to enter specially crafted SQL queries and perform unauthorized
remote code execution on the HCX manager.
Updates are available to remediate this vulnerability in affected VMware products.
Metrics
Affected Vendors & Products
References
History
Mon, 21 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:vmware:vmware_hcx:4.10.0:*:*:*:*:*:*:* |
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vmware
Vmware vmware Hcx |
|
CPEs | cpe:2.3:a:vmware:vmware_hcx:*:*:*:*:*:*:*:* | |
Vendors & Products |
Vmware
Vmware vmware Hcx |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager. Updates are available to remediate this vulnerability in affected VMware products. | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: vmware
Published: 2024-10-16T16:59:20.174Z
Updated: 2024-10-16T17:53:24.283Z
Reserved: 2024-06-19T22:31:57.187Z
Link: CVE-2024-38814
Vulnrichment
Updated: 2024-10-16T17:51:07.505Z
NVD
Status : Analyzed
Published: 2024-10-16T17:15:16.237
Modified: 2024-10-21T18:20:53.267
Link: CVE-2024-38814
Redhat
No data.