First published: Wed Oct 09 2024(Updated: )
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC AppSync | >=4.3.0.0<4.6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39586 is considered a high severity vulnerability due to its potential for information disclosure.
To fix CVE-2024-39586, upgrade Dell AppSync to version 4.6.0.3 or later.
CVE-2024-39586 affects Dell AppSync versions 4.3 through 4.6, specifically when used in environments where adjacent high privileged users can access the service.
CVE-2024-39586 is an XML External Entity Injection vulnerability.
An adjacent high privileged attacker could potentially exploit CVE-2024-39586 to gain unauthorized access to sensitive information.