VMware SD-WAN Orchestrator SQL Injection (CVE-2020-3984)

Related Vulnerabilities: CVE-2020-3984  

Check Point Reference: CPAI-2020-4139 Date Published: 28 Feb 2024 Severity: Medium Last Updated: Wednesday 28 February, 2024 Source: Industry Reference:CVE-2020-3984
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? VMware SD-WAN Orchestrator 3.4.0 and later, prior to 3.4.4
VMware SD-WAN Orchestrator 3.3.2
VMware SD-WAN Orchestrator 3.3.2 Patch 1
VMware SD-WAN Orchestrator 3.3.2 Patch 2 Vulnerability Description An SQL injection vulnerability exists in VMware SD-WAN Orchestrator. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.