PT-2024-32927 · Dell · Dell Avamar

Kentaro Kawane

·

Published

2024-12-10

·

Updated

2024-12-17

·

CVE-2024-47977

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Avamar versions 19.x
Description The issue is related to an Improper Neutralization of Special Elements used in an SQL Command, also known as a SQL Injection vulnerability. This could allow a low-privileged attacker with remote access to potentially exploit the vulnerability, leading to command execution.
Recommendations For version 19.x, update to a version that fixes the SQL Injection vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-47977
ZDI-24-1689
ZDI-24-1690
ZDI-24-1692

Affected Products

Dell Avamar