CVE-2018-6493

SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injection.
References
Link Resource
https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158014 Vendor Advisory
http://www.securitytracker.com/id/1040900 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/104131 Broken Link Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:network_operations_management_ultimate:2017.07:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_operations_management_ultimate:2017.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_operations_management_ultimate:2018.02:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:hp:network_automation:10.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.10:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.00:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.20:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.30:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.40:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.50:*:*:*:*:*:*:*

Information

Published : 2018-05-22 12:29

Updated : 2023-03-03 11:05


NVD link : CVE-2018-6493

Mitre link : CVE-2018-6493


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

hp

  • network_operations_management_ultimate
  • network_automation