PT-2021-11675 · Dell Emc · Dell Emc Avamar Server
Published
2021-01-14
·
Updated
2021-01-21
·
CVE-2020-29493
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DELL EMC Avamar Server versions 19.1 through 19.3
Description:
A SQL Injection Vulnerability exists in the Fitness Analyzer of DELL EMC Avamar Server, allowing a remote unauthenticated attacker to execute certain SQL commands on the application's backend database. This could lead to unauthorized read and write access to application data, potentially causing leakage or deletion of sensitive backup data.
Recommendations:
For versions 19.1 through 19.3, upgrade to a newer version at the earliest opportunity to resolve the issue. As a temporary workaround, consider restricting access to the Fitness Analyzer module to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Avamar Server