Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Apex Protection Storage
Subscribe
Dd3300
Subscribe
Dd6400
Subscribe
Dd6900
Subscribe
Dd9400
Subscribe
Dd9900
Subscribe
Dp4400
Subscribe
Dp5900
Subscribe
Emc Data Domain Os
Subscribe
Powerprotect Data Domain
Subscribe
Powerprotect Data Domain Management Center
Subscribe
Powerprotect Data Protection
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48640 | Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 21 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-11-21T16:20:17.129Z
Reserved: 2023-09-28T09:25:45.714Z
Link: CVE-2023-44284
Updated: 2024-08-02T19:59:51.944Z
Status : Modified
Published: 2023-12-14T16:15:46.880
Modified: 2024-11-21T08:25:35.263
Link: CVE-2023-44284
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD