HIGH🇵🇱 Wersja polska

CVE-2019-3752

CVSS 8.2v3.1pub. 2021-07-16upd. 2024-11-21

Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability to cause Denial of Service or information exposure by supplying specially crafted document type definitions (DTDs) in an XML request.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
  • Dell Emc Avamar Server

    APP
    Dell
    18.219.17.4.17.5.07.5.1
  • Dell Emc Integrated Data Protection Appliance

    APP
    Dell
    2.02.12.22.32.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSXXE
CWE
References

Related vulnerabilities

CVE-2020-5341CRITICAL9.8PL ✓same product

RCE poprzez Deserialization w Dell EMC Avamar Server i IDPA

CVE-2020-29495CRITICAL10.0PL ✓same product

RCE bez uwierzytelnienia w Dell EMC Avamar Server — command injection

CVE-2020-29493CRITICAL10.0PL ✓same product

SQL Injection w Dell EMC Avamar Server — nieautoryzowany dostęp do danych

CVE-2018-11066CRITICAL9.8PL ✓same product

RCE w Dell EMC Avamar Client Manager — zdalny dostęp bez uwierzytelnienia

CVE-2018-1217CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Dell EMC Avamar Installation Manager — ujawnienie danych uwierzytelniających