← Back

CVE-2024-47977

nvd nist
Published: Dec 10, 2024Modified: Aug 4, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

Affected (6)

Products: Dell: Avamar Server
1 product
Avamar Server
Configuration A
6 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Dell
Version 19.10
Version 19.10 sp1
Version 19.4
Version 19.7
Version 19.8
Version 19.9
Running on/withPlatform Versions
Dell
Avamar Data Store
Version gen4t
Dell
Avamar Data Store
Version gen5a

Timeline

No history available yet.