SQL Injection Vulnerability in Micro Focus Service Manager Automation Products
CVE-2020-9521

8.8HIGH

What is CVE-2020-9521?

A SQL injection vulnerability has been identified in Micro Focus Service Manager Automation products, which affects multiple versions from 2018 through 2019. This vulnerability permits attackers to manipulate SQL queries by improperly neutralizing special elements in the commands, potentially leading to unauthorized data access and compromise of database integrity.

Affected Version(s)

Micro Focus - Service Manager Automation (SMA) 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.