Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-52538

Disclosure Date: December 10, 2024 (last updated February 05, 2025)
Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Attacker Value
Unknown

CVE-2024-47977

Disclosure Date: December 10, 2024 (last updated February 05, 2025)
Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Attacker Value
Unknown

CVE-2024-47484

Disclosure Date: December 10, 2024 (last updated February 05, 2025)
Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Attacker Value
Unknown

CVE-2021-36317

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
Attacker Value
Unknown

CVE-2021-36318

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.
Attacker Value
Unknown

CVE-2021-36316

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability in AUI. A malicious user with high privileges could potentially exploit this vulnerability, leading to the disclosure of the AUI info and performing some unauthorized operation on the AUI.
Attacker Value
Unknown

CVE-2021-21511

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could potentially exploit this vulnerability, to gain unauthorized read or modification access to other users' backup data.