VMware SD-WAN Orchestrator 3.3.2 before 3.3.2 P3, 3.4.x before 3.4.4, and 4.0.x before 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WAN Orchestrator user may inject code into SQL queries which may lead to information disclosure.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
vmware sd-wan orchestrator 3.3.2 |
||
vmware sd-wan orchestrator |