CVE-2024-47484

Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:dell:avamar_server:19.4:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.7:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.8:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:-:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:sp1:*:*:*:*:*:*
OR cpe:2.3:h:dell:avamar_data_store:gen4t:*:*:*:*:*:*:*
cpe:2.3:h:dell:avamar_data_store:gen5a:*:*:*:*:*:*:*

History

04 Feb 2025, 16:11

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000258636/dsa-2024-489-security-update-for-dell-avamar-and-dell-avamar-virtual-edition-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000258636/dsa-2024-489-security-update-for-dell-avamar-and-dell-avamar-virtual-edition-security-update-for-multiple-vulnerabilities - Vendor Advisory
CPE cpe:2.3:a:dell:avamar_server:19.8:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.4:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:-:*:*:*:*:*:*
cpe:2.3:h:dell:avamar_data_store:gen4t:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.7:*:*:*:*:*:*:*
cpe:2.3:h:dell:avamar_data_store:gen5a:*:*:*:*:*:*:*
First Time Dell
Dell avamar Data Store
Dell avamar Server

16 Dec 2024, 11:15

Type Values Removed Values Added
Summary
  • (es) Dell Avamar, versión 19.9, contiene una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ("inyección SQL"). Un atacante no autenticado con acceso remoto podría aprovechar esta vulnerabilidad, lo que provocaría la ejecución del comando.
Summary (en) Dell Avamar, version(s) 19.9, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. (en) Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

10 Dec 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 11:15

Updated : 2025-02-04 16:11


NVD link : CVE-2024-47484

Mitre link : CVE-2024-47484

CVE.ORG link : CVE-2024-47484


JSON object : View

Products Affected

dell

  • avamar_data_store
  • avamar_server
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')