CVE-2020-9521
Summary
| CVE | CVE-2020-9521 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-26 15:15:00 UTC |
| Updated | 2023-11-07 03:26:00 UTC |
| Description | An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead to the product being vulnerable to SQL injection. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microfocus | Service Manager Automation | 2018.02 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2018.05 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2018.08 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2019.02 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2019.05 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2019.08 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2018.02 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2018.05 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2018.08 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2019.02 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2019.05 | All | All | All |
| Application | Microfocus | Service Manager Automation | 2019.08 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MySupport - Micro Focus Software Support | MISC | softwaresupport.softwaregrp.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.