ZeroHour

CVE-2023-44284

CVSS 3.1
4.3 medium
EPSS
<1%p45
Published
()
Modified
Description

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.

Vendors
dell
Products
powerprotect data protection, apex protection storage, powerprotect data domain, powerprotect data domain management center, emc data domain os
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.