CVE Published: 08/07/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: vmware |
Vendor: n/a |
Product: VMware SD-WAN by VeloCloud Status : PUBLISHED
CVE-2020-3973 Description
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.