CVE-2020-9521

An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead to the product being vulnerable to SQL injection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microfocus:service_manager_automation:2018.02:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager_automation:2018.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager_automation:2018.08:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager_automation:2019.02:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager_automation:2019.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager_automation:2019.08:*:*:*:*:*:*:*

History

07 Nov 2023, 03:26

Type Values Removed Values Added
References (MISC) https://softwaresupport.softwaregrp.com/doc/KM03630615 - Patch, Vendor Advisory () https://softwaresupport.softwaregrp.com/doc/KM03630615 -

Information

Published : 2020-03-26 15:15

Updated : 2024-02-28 17:47


NVD link : CVE-2020-9521

Mitre link : CVE-2020-9521

CVE.ORG link : CVE-2020-9521


JSON object : View

Products Affected

microfocus

  • service_manager_automation
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')