Executive brief
Veritas InfoScale Operations Manager (VIOM), a tool used for managing complex data center storage and server environments, contains a security vulnerability. An attacker can exploit this flaw to gain higher levels of access than they should have, potentially allowing them to view or modify sensitive management data. This could lead to unauthorized changes in the IT infrastructure or data exposure.
Technical details
A SQL injection vulnerability exists in the web management interface of Veritas InfoScale Operations Manager (VIOM) in versions prior to 9.1.3. The flaw allows a remote attacker to inject malicious SQL commands into database queries. By exploiting this vulnerability, an attacker can bypass authentication or escalate their privileges within the application. This could lead to unauthorized access to the underlying database and full administrative control over the VIOM instance. Users are advised to upgrade to version 9.1.3 or later to remediate this issue.
Affected products
- Veritas InfoScale Operations Manager (VIOM) Before v9.1.3
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory
References
- https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=1000766080&articleTitle=InfoScale_Operations_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925
- https://www.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-166757640