CVE-2024-39586: XEE
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39586?
CVE-2024-39586 is considered a high severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2024-39586?
To fix CVE-2024-39586, upgrade Dell AppSync to version 4.6.0.3 or later.
Who is affected by CVE-2024-39586?
CVE-2024-39586 affects Dell AppSync versions 4.3 through 4.6, specifically when used in environments where adjacent high privileged users can access the service.
What type of vulnerability is CVE-2024-39586?
CVE-2024-39586 is an XML External Entity Injection vulnerability.
What can an attacker achieve with CVE-2024-39586?
An adjacent high privileged attacker could potentially exploit CVE-2024-39586 to gain unauthorized access to sensitive information.