CVE-2020-24623
Summary
| CVE | CVE-2020-24623 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-18 17:15:00 UTC |
| Updated | 2020-09-30 13:45:00 UTC |
| Description | A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft Hyper-V (VHD). |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hpe | Universal Api Framework | All | All | All | All |
| Application | Hpe | Universal Api Framework | All | All | All | All |
| Application | Hpe | Universal Api Framework | All | All | All | All |
| Application | Hpe | Universal Api Framework | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-20-1208 | Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| Document Display | HPE Support Center | MISC | support.hpe.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.