Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
References
Configurations
Configuration 1 (hide)
|
History
31 Oct 2024, 00:01
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
Summary |
|
|
CPE | cpe:2.3:a:dell:data_lakehouse:1.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:dell:data_lakehouse:1.1.0.0:*:*:*:*:*:*:* |
|
First Time |
Dell
Dell data Lakehouse |
|
References | () https://www.dell.com/support/kbdoc/en-us/000240535/dsa-2024-419-security-update-for-dell-data-lakehouse-system-software-for-multiple-third-party-component-vulnerabilities - Vendor Advisory |
25 Oct 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-25 11:15
Updated : 2024-10-31 00:01
NVD link : CVE-2024-47483
Mitre link : CVE-2024-47483
CVE.ORG link : CVE-2024-47483
JSON object : View
Products Affected
dell
- data_lakehouse
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')