Medium severity6.6NVD Advisory· Published Nov 5, 2020· Updated Jun 17, 2026
CVE-2020-12147
CVE-2020-12147
Description
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing.
Affected products
3All versions affected prior to Silver Peak Unity Orchestrator 8.9.11++ 2 more
- (no CPE)range: All versions affected prior to Silver Peak Unity Orchestrator 8.9.11+
- (no CPE)range: <8.9.11, <8.10.11, <9.0.1
- cpe:2.3:a:silver-peak:unity_orchestrator:*:*:*:*:*:*:*:*range: <8.9.11\+
Patches
Vulnerability mechanics
References
1- www.silver-peak.com/support/user-documentation/security-advisoriesnvdVendor Advisory
News mentions
0No linked articles in our index yet.