CVE-2024-47977

Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:dell:avamar_server:19.4:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.7:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.8:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:-:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:sp1:*:*:*:*:*:*
OR cpe:2.3:h:dell:avamar_data_store:gen4t:*:*:*:*:*:*:*
cpe:2.3:h:dell:avamar_data_store:gen5a:*:*:*:*:*:*:*

History

04 Feb 2025, 16:12

Type Values Removed Values Added
First Time Dell
Dell avamar Data Store
Dell avamar Server
CPE cpe:2.3:a:dell:avamar_server:19.8:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.4:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:-:*:*:*:*:*:*
cpe:2.3:h:dell:avamar_data_store:gen4t:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.7:*:*:*:*:*:*:*
cpe:2.3:h:dell:avamar_data_store:gen5a:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000258636/dsa-2024-489-security-update-for-dell-avamar-and-dell-avamar-virtual-edition-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000258636/dsa-2024-489-security-update-for-dell-avamar-and-dell-avamar-virtual-edition-security-update-for-multiple-vulnerabilities - Vendor Advisory

16 Dec 2024, 11:15

Type Values Removed Values Added
Summary
  • (es) Dell Avamar, versión 19.9, contiene una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ("inyección SQL"). Un atacante con privilegios reducidos y acceso remoto podría aprovechar esta vulnerabilidad y provocar la ejecución del comando.
Summary (en) Dell Avamar, version(s) 19.9, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. (en) Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

10 Dec 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 11:15

Updated : 2025-02-04 16:12


NVD link : CVE-2024-47977

Mitre link : CVE-2024-47977

CVE.ORG link : CVE-2024-47977


JSON object : View

Products Affected

dell

  • avamar_data_store
  • avamar_server
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')