Vulnerability Description
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silver-Peak | Unity Orchestrator | < 8.9.11\+ |
Related Weaknesses (CWE)
References
- https://www.silver-peak.com/support/user-documentation/security-advisoriesVendor Advisory
- https://www.silver-peak.com/support/user-documentation/security-advisoriesVendor Advisory
FAQ
What is CVE-2020-12147?
CVE-2020-12147 is a vulnerability with a CVSS score of 6.6 (MEDIUM). In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution RE...
How severe is CVE-2020-12147?
CVE-2020-12147 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12147?
Check the references section above for vendor advisories and patch information. Affected products include: Silver-Peak Unity Orchestrator.