CVE-2023-38547
critical · 9.8A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.
9.8
CVSS
18.9%
EPSS (exploit prob.)
97th
EPSS percentile
2023-11-07
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| veeam | one | 11.0.0.1379 |
| veeam | one | 11.0.1.1880 |
| veeam | one | 12.0.0.2498 |
| veeam | one | 12.0.1.2591 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-38547