Impact
A flaw in Veeam ONE permits a user with limited privileges to inject arbitrary SQL commands, which can expose sensitive database information. The vulnerability is rooted in improper handling of user input, aligning with CWE‑89. The primary risk is data confidentiality loss through unauthorized data extraction.
Affected Systems
The affected product is Veeam ONE. No specific version information is provided in the CNA data, so all releases of the product could potentially be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity level. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. The most likely attack vector requires the attacker to have a low‑privileged account or to exploit the application from within the environment. Once the vulnerable input is supplied, the attacker can retrieve database contents, potentially impacting confidentiality and the integrity of stored data.
OpenCVE Enrichment