Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NDell Powerflex Manager
APPDell4.5.5 – 4.5.5.2 (excl.)5.1.0 – 5.1.0.1 (excl.)
Related vulnerabilities
OS Command Injection w Dell PowerFlex Manager — wykonanie poleceń jako root
Krytyczna podatność RCE w produktach Dell PowerFlex, InsightIQ i Data Lakehouse
SQL Injection w Dell PowerFlex Manager — ujawnienie informacji
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An u...
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted C...