{"api_version":"1","generated_at":"2026-07-23T14:55:35+00:00","cve":"CVE-2020-36530","urls":{"html":"https://cve.report/CVE-2020-36530","api":"https://cve.report/api/cve/CVE-2020-36530.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-36530","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-36530"},"summary":{"title":"CVE-2020-36530","description":"A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2022-06-07 18:15:00","updated_at":"2022-06-14 15:03:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"http://seclists.org/fulldisclosure/2020/Oct/5","name":"http://seclists.org/fulldisclosure/2020/Oct/5","refsource":"MISC","tags":[],"title":"Full Disclosure: SEC Consult SA-20201002-0 :: Multiple Vulnerabilities in SevOne Network Management System (NMS)","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?id.162262","name":"https://vuldb.com/?id.162262","refsource":"MISC","tags":[],"title":"CVE-2020-36530 | SevOne Network Management System Alert Summary sql injection","mime":"text/html","httpstatus":"429","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-36530","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-36530","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"36530","vulnerable":"1","versionEndIncluding":"5.7.2.22","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"sevone_network_performance_management","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-36530","TITLE":"SevOne Network Management System Alert Summary sql injection","REQUESTER":"cna@vuldb.com","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"generator":"vuldb.com","affects":{"vendor":{"vendor_data":[{"vendor_name":"SevOne","product":{"product_data":[{"product_name":"Network Management System","version":{"version_data":[{"version_value":"5.7.2.0"},{"version_value":"5.7.2.1"},{"version_value":"5.7.2.2"},{"version_value":"5.7.2.3"},{"version_value":"5.7.2.4"},{"version_value":"5.7.2.5"},{"version_value":"5.7.2.6"},{"version_value":"5.7.2.7"},{"version_value":"5.7.2.8"},{"version_value":"5.7.2.9"},{"version_value":"5.7.2.10"},{"version_value":"5.7.2.11"},{"version_value":"5.7.2.12"},{"version_value":"5.7.2.13"},{"version_value":"5.7.2.14"},{"version_value":"5.7.2.15"},{"version_value":"5.7.2.16"},{"version_value":"5.7.2.17"},{"version_value":"5.7.2.18"},{"version_value":"5.7.2.19"},{"version_value":"5.7.2.20"},{"version_value":"5.7.2.21"},{"version_value":"5.7.2.22"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-89 SQL Injection"}]}]},"description":{"description_data":[{"lang":"eng","value":"A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely."}]},"credit":"Calvin Phang","impact":{"cvss":{"version":"3.1","baseScore":"6.3","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}},"references":{"reference_data":[{"url":"http://seclists.org/fulldisclosure/2020/Oct/5","refsource":"MISC","name":"http://seclists.org/fulldisclosure/2020/Oct/5"},{"url":"https://vuldb.com/?id.162262","refsource":"MISC","name":"https://vuldb.com/?id.162262"}]}},"nvd":{"publishedDate":"2022-06-07 18:15:00","lastModifiedDate":"2022-06-14 15:03:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6},"severity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:sevone_network_performance_management:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7.2.0","versionEndIncluding":"5.7.2.22","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}