Description
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject malicious report generation scripts in the server. This may lead to OS command execution as the regular user runs the DPA service on the affected system.
Published: 2020-03-18
Score: 7.2 High
EPSS: 2.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-8329 Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject malicious report generation scripts in the server. This may lead to OS command execution as the regular user runs the DPA service on the affected system.
History

No history.

Subscriptions

Dell Emc Data Protection Advisor Emc Idpa Dp4400 Emc Idpa Dp5800 Emc Idpa Dp8300 Emc Idpa Dp8800 Emc Integrated Data Protection Appliance Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T03:58:36.117Z

Reserved: 2019-10-29T00:00:00.000Z

Link: CVE-2019-18582

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-18T19:15:16.623

Modified: 2024-11-21T04:33:20.460

Link: CVE-2019-18582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses