Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
No history.
Information
Published : 2023-12-14 16:15
Updated : 2023-12-27 19:31
NVD link : CVE-2023-44284
Mitre link : CVE-2023-44284
CVE.ORG link : CVE-2023-44284
JSON object : View
Products Affected
dell
- dd6400
- powerprotect_data_protection
- dd9400
- dp4400
- dd9900
- emc_data_domain_os
- dp5900
- apex_protection_storage
- powerprotect_data_domain
- dd6900
- powerprotect_data_domain_management_center
- dd3300
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')