CVE-2023-44284: SQL Injection
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44284?
CVE-2023-44284 is categorized as a low severity vulnerability.
How can I fix CVE-2023-44284?
To remediate CVE-2023-44284, upgrade your Dell PowerProtect DD and related software to version 7.13.0.10 or later.
What types of attacks are associated with CVE-2023-44284?
CVE-2023-44284 allows remote low privileged attackers to execute SQL commands on the application's backend database.
Which versions of Dell PowerProtect are affected by CVE-2023-44284?
CVE-2023-44284 affects Dell PowerProtect DD versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and 6.2.1.110.
What are the potential impacts of exploiting CVE-2023-44284?
Exploitation of CVE-2023-44284 could lead to unauthorized access and manipulation of the backend database.