CVE-2020-9521

HIGH

Micro Focus Service Manager Automation 2018.02-2019.08 - SQL Injection

Title source: llm
STIX 2.1

Description

An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead to the product being vulnerable to SQL injection.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0030
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (6)
microfocus/service_manager_automation 2018.02
microfocus/service_manager_automation 2018.05
microfocus/service_manager_automation 2018.08
microfocus/service_manager_automation 2019.02
microfocus/service_manager_automation 2019.05
microfocus/service_manager_automation 2019.08
Published Mar 26, 2020
Tracked Since Feb 18, 2026