CVE-2024-39586

D

ell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:emc_appsync:*:*:*:*:*:*:*:*

History

17 Oct 2024, 14:30

Type Values Removed Values Added
CPE cpe:2.3:a:dell:emc_appsync:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000234216/dsa-2024-420-security-update-for-dell-emc-appsync-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000234216/dsa-2024-420-security-update-for-dell-emc-appsync-for-multiple-vulnerabilities - Vendor Advisory
First Time Dell
Dell emc Appsync
CVSS v2 : unknown
v3 : 2.9
v2 : unknown
v3 : 4.3

10 Oct 2024, 12:51

Type Values Removed Values Added
Summary
  • (es) Dell AppSync Server, versión 4.3 a 4.6, contiene una vulnerabilidad de inyección de entidad externa XML. Un atacante adyacente con privilegios elevados podría aprovechar esta vulnerabilidad, lo que daría lugar a la divulgación de información.

09 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 07:15

Updated : 2024-10-17 14:30


NVD link : CVE-2024-39586

Mitre link : CVE-2024-39586

CVE.ORG link : CVE-2024-39586


JSON object : View

Products Affected
CWE
CWE-611

Improper Restriction of XML External Entity Reference