CVE-2018-6493

SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:network_operations_management_ultimate:2017.07:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_operations_management_ultimate:2017.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_operations_management_ultimate:2018.02:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:hp:network_automation:10.00:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.10:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.20:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.30:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.40:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.50:*:*:*:*:*:*:*

History

07 Nov 2023, 02:59

Type Values Removed Values Added
References (SECTRACK) http://www.securitytracker.com/id/1040900 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1040900 -
References (CONFIRM) https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158014 - Vendor Advisory () https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158014 -
References (BID) http://www.securityfocus.com/bid/104131 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/104131 -

03 Mar 2023, 19:05

Type Values Removed Values Added
References (BID) http://www.securityfocus.com/bid/104131 - Third Party Advisory, VDB Entry (BID) http://www.securityfocus.com/bid/104131 - Broken Link, Third Party Advisory, VDB Entry

Information

Published : 2018-05-22 19:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-6493

Mitre link : CVE-2018-6493

CVE.ORG link : CVE-2018-6493


JSON object : View

Products Affected

hp

  • network_operations_management_ultimate
  • network_automation
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')