cbcvebase.
CVE-2024-22280
published 2024-07-11

CVE-2024-22280: VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter…

high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.

Affected

3 ranges
VendorProductVersion rangeFixed in
vmwarearia_automation< 8.17.08.17.0
vmwarecloud_foundation4.0 – 5.0
vmwarevmware_aria_automation>= 8.x < 8.17.08.17.0