Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity.
An attacker with an account that already has high privileges can remotely, without user interaction, exploit improperly implemented access control in the product. The vulnerability allows bypassing the assigned scope of permissions and escalating them to an even higher level. The vulnerability operates within a changed scope (Scope: Changed), which means its effects may extend beyond the directly attacked system component.
An attacker can obtain unauthorized access with elevated privileges, which threatens the confidentiality, integrity, and availability of the system and may lead to compromise of customer data stored in the Dell Data Lakehouse environment.
Dell recommends upgrading the product to version 1.6.0.0 or later as soon as possible. Detailed information is available in Dell's security bulletin DSA-2025-375 at: https://www.dell.com/support/kbdoc/en-us/000390529/dsa-2025-375-security-update-for-dell-data-lakehouse-multiple-vulnerabilities
Dell Data Lakehouse in versions prior to 1.6.0.0
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDell Data Lakehouse
APPDell< 1.6.0.0
Related vulnerabilities
Krytyczna podatność RCE w produktach Dell PowerFlex, InsightIQ i Data Lakehouse
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior t...
Dell Data Lakehouse, versions prior to 1.5.0.0, contains an Execution with Unnecessary Privileges vulnerabilit...
Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unaut...
Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in th...