Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
21 Nov 2024, 08:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.dell.com/support/kbdoc/en-us/000220264/dsa-2023-412-dell-technologies-powerprotect-security-update-for-multiple-security-vulnerabilities - Vendor Advisory |
27 Dec 2023, 19:31
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dell apex Protection Storage
Dell dp5900 Dell dd6400 Dell Dell dd9900 Dell emc Data Domain Os Dell dd6900 Dell powerprotect Data Domain Dell dp4400 Dell powerprotect Data Domain Management Center Dell dd3300 Dell dd9400 Dell powerprotect Data Protection |
|
CPE | cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:* cpe:2.3:a:dell:powerprotect_data_protection:*:*:*:*:*:*:*:* cpe:2.3:a:dell:apex_protection_storage:*:*:*:*:*:*:*:* cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:lts2023:*:*:* cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:virtual:*:*:* cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:* cpe:2.3:a:dell:powerprotect_data_domain_management_center:*:*:*:*:*:*:*:* cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:* cpe:2.3:h:dell:dp5900:-:*:*:*:*:*:*:* cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:* cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:lts2022:*:*:* cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:*:*:*:* cpe:2.3:o:dell:powerprotect_data_domain_management_center:*:*:*:*:lts2023:*:*:* cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:* cpe:2.3:o:dell:powerprotect_data_domain_management_center:*:*:*:*:lts2022:*:*:* cpe:2.3:h:dell:dp4400:-:*:*:*:*:*:*:* |
|
References | () https://www.dell.com/support/kbdoc/en-us/000220264/dsa-2023-412-dell-technologies-powerprotect-security-update-for-multiple-security-vulnerabilities - Vendor Advisory |
14 Dec 2023, 17:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-14 16:15
Updated : 2024-11-21 08:25
NVD link : CVE-2023-44284
Mitre link : CVE-2023-44284
CVE.ORG link : CVE-2023-44284
JSON object : View
Products Affected
dell
- dd9400
- powerprotect_data_domain_management_center
- emc_data_domain_os
- dd6400
- apex_protection_storage
- dp4400
- powerprotect_data_protection
- powerprotect_data_domain
- dd3300
- dd6900
- dp5900
- dd9900
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')