PT-2020-9968 · Dell Emc · Dell Emc Data Protection Advisor

Published

2020-03-18

·

Updated

2020-03-24

·

CVE-2019-18582

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5 Dell EMC Data Protection Advisor versions 18.2 prior to patch 83 Dell EMC Data Protection Advisor versions 19.1 prior to patch 71
Description: The issue concerns a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject malicious report generation scripts in the server, leading to OS command execution as the regular user runs the DPA service on the affected system.
Recommendations: For versions 6.3, 6.4, 6.5, apply the necessary patches to fix the server-side template injection vulnerability. For version 18.2, apply patch 83 or later to resolve the issue. For version 19.1, apply patch 71 or later to resolve the issue.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18582

Affected Products

Dell Emc Data Protection Advisor