VYPR

Velocloud Orchestrator

by VMware

CVEs (2)

  • CVE-2020-3973HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.01

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

  • CVE-2019-5533MedOct 29, 2019
    risk 0.29cvss 4.3epss 0.18

    In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. Among the information is username, first and last name, phone…