Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
History

Thu, 31 Oct 2024 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell data Lakehouse
CPEs cpe:2.3:a:dell:data_lakehouse:1.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:data_lakehouse:1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Dell
Dell data Lakehouse

Fri, 25 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Oct 2024 11:15:00 +0000

Type Values Removed Values Added
Description Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2024-10-25T10:59:45.160Z

Updated: 2024-10-25T13:53:16.503Z

Reserved: 2024-09-25T05:22:37.838Z

Link: CVE-2024-47483

cve-icon Vulnrichment

Updated: 2024-10-25T13:53:12.695Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-25T11:15:17.930

Modified: 2024-10-31T00:01:05.127

Link: CVE-2024-47483

cve-icon Redhat

No data.