Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
References
Configurations
History
17 Oct 2024, 14:30
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:dell:emc_appsync:*:*:*:*:*:*:*:* | |
First Time |
Dell
Dell emc Appsync |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
References | () https://www.dell.com/support/kbdoc/en-us/000234216/dsa-2024-420-security-update-for-dell-emc-appsync-for-multiple-vulnerabilities - Vendor Advisory |
10 Oct 2024, 12:51
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Oct 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-09 07:15
Updated : 2024-10-17 14:30
NVD link : CVE-2024-39586
Mitre link : CVE-2024-39586
CVE.ORG link : CVE-2024-39586
JSON object : View
Products Affected
dell
- emc_appsync
CWE
CWE-611
Improper Restriction of XML External Entity Reference