Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability to cause Denial of Service or information exposure by supplying specially crafted document type definitions (DTDs) in an XML request.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:HDell Emc Avamar Server
APPDell18.219.17.4.17.5.07.5.1Dell Emc Integrated Data Protection Appliance
APPDell2.02.12.22.32.4
Powiązane podatności
RCE poprzez Deserialization w Dell EMC Avamar Server i IDPA
RCE bez uwierzytelnienia w Dell EMC Avamar Server — command injection
SQL Injection w Dell EMC Avamar Server — nieautoryzowany dostęp do danych
RCE w Dell EMC Avamar Client Manager — zdalny dostęp bez uwierzytelnienia
Brak kontroli dostępu w Dell EMC Avamar Installation Manager — ujawnienie danych uwierzytelniających