HIGH🇬🇧 English

CVE-2019-3752

CVSS 8.2v3.1pub. 2021-07-16upd. 2024-11-21

Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability to cause Denial of Service or information exposure by supplying specially crafted document type definitions (DTDs) in an XML request.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
  • Dell Emc Avamar Server

    APP
    Dell
    18.219.17.4.17.5.07.5.1
  • Dell Emc Integrated Data Protection Appliance

    APP
    Dell
    2.02.12.22.32.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoSXXE
CWE
Referencje

Powiązane podatności

CVE-2020-5341CRITICAL9.8PL ✓ten sam produkt

RCE poprzez Deserialization w Dell EMC Avamar Server i IDPA

CVE-2020-29495CRITICAL10.0PL ✓ten sam produkt

RCE bez uwierzytelnienia w Dell EMC Avamar Server — command injection

CVE-2020-29493CRITICAL10.0PL ✓ten sam produkt

SQL Injection w Dell EMC Avamar Server — nieautoryzowany dostęp do danych

CVE-2018-11066CRITICAL9.8PL ✓ten sam produkt

RCE w Dell EMC Avamar Client Manager — zdalny dostęp bez uwierzytelnienia

CVE-2018-1217CRITICAL9.8PL ✓ten sam produkt

Brak kontroli dostępu w Dell EMC Avamar Installation Manager — ujawnienie danych uwierzytelniających