First published: Thu Dec 14 2023(Updated: )
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Dell PowerProtect Data Protection | <2.7.6 | |
Any of | ||
Dell DP4400 | ||
Dell DP5900 Firmware | ||
All of | ||
Any of | ||
Dell Apex Protection Storage | <6.2.1.110 | |
Dell Apex Protection Storage | >=7.0<7.10.1.15 | |
Dell PowerProtect Data Domain Management Center | <6.2.1.110 | |
Dell PowerProtect Data Domain Management Center | >=7.0<7.12.0.0 | |
Dell PowerProtect Data Domain Management Center | <6.2.1.110 | |
Dell PowerProtect Data Domain Management Center | >=7.0<7.13.0.10 | |
EMC Data Domain Operating System | <6.2.1.110 | |
EMC Data Domain Operating System | >=7.0<7.12.0.0 | |
EMC Data Domain Operating System | >=7.7<7.7.5.25 | |
EMC Data Domain Operating System | >=7.10<7.10.1.15 | |
Dell PowerProtect Data Domain Management Center | >=7.7<7.7.5.25 | |
Dell PowerProtect Data Domain Management Center | >=7.10<7.10.1.15 | |
Any of | ||
Dell DD3300 | ||
Dell DD6400 | ||
Dell DD6900 | ||
Dell DD9400 | ||
Dell Dd9900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44284 is categorized as a low severity vulnerability.
To remediate CVE-2023-44284, upgrade your Dell PowerProtect DD and related software to version 7.13.0.10 or later.
CVE-2023-44284 allows remote low privileged attackers to execute SQL commands on the application's backend database.
CVE-2023-44284 affects Dell PowerProtect DD versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and 6.2.1.110.
Exploitation of CVE-2023-44284 could lead to unauthorized access and manipulation of the backend database.