Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Aug 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 04 Feb 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dell
Dell avamar Data Store Dell avamar Server |
|
CPEs | cpe:2.3:a:dell:avamar_server:19.10:-:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.10:sp1:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.4:*:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.7:*:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.8:*:*:*:*:*:*:* cpe:2.3:a:dell:avamar_server:19.9:*:*:*:*:*:*:* cpe:2.3:h:dell:avamar_data_store:gen4t:*:*:*:*:*:*:* cpe:2.3:h:dell:avamar_data_store:gen5a:*:*:*:*:*:*:* |
|
Vendors & Products |
Dell
Dell avamar Data Store Dell avamar Server |
Mon, 16 Dec 2024 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dell Avamar, version(s) 19.9, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
Tue, 10 Dec 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Dec 2024 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dell Avamar, version(s) 19.9, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: dell
Published: 2024-12-10T10:16:04.791Z
Updated: 2025-08-04T18:40:30.859Z
Reserved: 2024-11-12T06:04:07.775Z
Link: CVE-2024-52538

Updated: 2024-12-10T19:39:59.236Z

Status : Modified
Published: 2024-12-10T11:15:07.690
Modified: 2025-08-04T19:15:30.007
Link: CVE-2024-52538

No data.