QID 378829

Date Published: 2023-09-20

QID 378829: Veritas InfoScale Operations Manager (VIOM) Multiple Security Vulnerabilities (VTS23-007)

Veritas InfoScale Operations Manager is a comprehensive management platform, for Symantec Storage Foundation and Cluster Server environments, that helps you optimize your data center assets, with a solution to centralize visibility and control, ensure availability, scale operations, increase storage utilization, and maintain compliance.

Affected Versions:
Veritas InfoScale Operations Manager (VIOM) versions 7.0, 7.1, 7.2, 7.3, 7.3.1, 7.4, 7.4.2, 8.0. Earlier unsupported versions may be affected as well.
QID Detection Logic:(Authenticated)
It checks for vulnerable version of Veritas InfoScale Operations Manager using version of .exe file.

This allows attackers to submit arbitrary SQL commands on the back-end database and An attacker with root/administrator level privileges can use this vulnerability to read sensitive data stored on the servers, modify data or server configuration and delete data or application configuration.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    For more information please visit Veritas InfoScale Operations Manager advisory VTS23-007

    CVEs related to QID 378829

    Software Advisories
    Advisory ID Software Component Link
    VTS23-007 URL Logo www.veritas.com/content/support/en_US/security/VTS23-007