ZDI-24-1691: Dell Avamar Fitness Analyzer API SQL Injection Information Disclosure Vulnerability
Published Dec 16, 2024
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dell Avamar. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2024-52538.
Affected Software
1 affected component
Dell Avamar
Event History
Dec 16, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1691?
The severity of ZDI-24-1691 is rated at 7.1 on the CVSS scale.
2
How do I fix ZDI-24-1691?
To fix ZDI-24-1691, ensure that you apply the latest security updates provided by Dell for Avamar.
3
What information can be disclosed due to ZDI-24-1691?
ZDI-24-1691 allows remote attackers to disclose sensitive information from affected installations of Dell Avamar.
4
Does ZDI-24-1691 require authentication to exploit?
Yes, ZDI-24-1691 requires authentication to be exploited.
5
What vulnerability does ZDI-24-1691 correspond to in CVE?
ZDI-24-1691 corresponds to CVE-2024-52538.