D
ell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
References
Configurations
Configuration 1 (hide)
|
History
31 Oct 2024, 00:01
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CPE | cpe:2.3:a:dell:data_lakehouse:1.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:dell:data_lakehouse:1.1.0.0:*:*:*:*:*:*:* |
|
| References | () https://www.dell.com/support/kbdoc/en-us/000240535/dsa-2024-419-security-update-for-dell-data-lakehouse-system-software-for-multiple-third-party-component-vulnerabilities - Vendor Advisory | |
| First Time |
Dell
Dell data Lakehouse |
|
| Summary |
|
25 Oct 2024, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-10-25 11:15
Updated : 2024-10-31 00:01
NVD link : CVE-2024-47483
Mitre link : CVE-2024-47483
CVE.ORG link : CVE-2024-47483
JSON object : View
Products Affected
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')