Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Aug 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 04 Feb 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dell
Dell avamar Data Store Dell avamar Server |
|
CPEs | cpe:2.3:a:dell:avamar_server:19.10:-:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.10:sp1:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.4:*:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.7:*:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.8:*:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.9:*:*:*:*:*:*:* cpe:2.3:h:dell:avamar_data_store:gen4t:*:*:*:*:*:*:* cpe:2.3:h:dell:avamar_data_store:gen5a:*:*:*:*:*:*:* |
|
Vendors & Products |
Dell
Dell avamar Data Store Dell avamar Server |
Mon, 16 Dec 2024 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dell Avamar, version(s) 19.9, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
Tue, 10 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Dec 2024 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dell Avamar, version(s) 19.9, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: dell
Published: 2024-12-10T10:26:54.861Z
Updated: 2025-08-04T18:39:35.486Z
Reserved: 2024-10-08T04:36:39.201Z
Link: CVE-2024-47977

Updated: 2024-12-10T15:39:56.438Z

Status : Modified
Published: 2024-12-10T11:15:07.550
Modified: 2025-08-04T19:15:29.837
Link: CVE-2024-47977

No data.