A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.
References
History

Thu, 06 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2023-11-07T06:17:31.617Z

Updated: 2025-03-06T15:33:18.141Z

Reserved: 2023-07-20T01:00:12.444Z

Link: CVE-2023-38547

cve-icon Vulnrichment

Updated: 2024-08-02T17:46:55.771Z

cve-icon NVD

Status : Modified

Published: 2023-11-07T07:15:07.387

Modified: 2025-03-06T16:15:42.203

Link: CVE-2023-38547

cve-icon Redhat

No data.