ZDI-24-1692: Dell Avamar Fitness Analyzer API SQL Injection Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dell Avamar. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2024-47977.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1692?
The vulnerability ZDI-24-1692 has a CVSS rating of 7.1, indicating a high level of severity.
How do I fix ZDI-24-1692?
To mitigate vulnerability ZDI-24-1692, ensure that you apply the latest security patches provided by Dell for Avamar.
What type of attacks can exploit ZDI-24-1692?
Vulnerability ZDI-24-1692 can be exploited by remote attackers to disclose sensitive information, requiring authentication.
Which software versions are affected by ZDI-24-1692?
The ZDI-24-1692 vulnerability affects installations of Dell Avamar, although specific version numbers are not listed.
What is the CVE associated with ZDI-24-1692?
The associated CVE for vulnerability ZDI-24-1692 is CVE-2024-47977.