Veritas InfoScale Operations Manager (VIOM) 7.4.2.400

CPE Details

Veritas InfoScale Operations Manager (VIOM) 7.4.2.400
7.4.2.400
2022-03-09
15h41 +00:00
2022-03-13
02h25 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:veritas:infoscale_operations_manager:7.4.2.400:*:*:*:*:*:*:*

Informations

Vendor

veritas

Product

infoscale_operations_manager

Version

7.4.2.400

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-38404 2023-07-16 22h00 +00:00 The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
8.8
High
CVE-2023-32568 2023-05-10 00h00 +00:00 An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage this to read sensitive data stored on the servers, modify data or server configuration, and delete data or application configuration.
7.2
High
CVE-2023-32569 2023-05-10 00h00 +00:00 An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the back-end database to create, read, update, or delete any sensitive data stored in the database.
9.8
Critical
CVE-2022-26484 2022-03-04 17h23 +00:00 An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By manipulating the resource name in GET requests referring to files with absolute paths, it is possible to access arbitrary files stored on the filesystem, including application source code, configuration files, and critical system files.
4.9
Medium
CVE-2022-26483 2022-03-04 17h23 +00:00 An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter (which reflect the user input without sanitization).
4.8
Medium