CVE-2022-34397

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:evasa_provider_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:eem:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:eem:*:*:*

History

21 Nov 2024, 07:09

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-for-powermax-dell-unisphere-for-powermax-vapp-dell-solutions-enabler-vapp-dell-unisphere-360-dell-vasa-provider-vapp-and-dell-powermax-emb-mgmt-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-for-powermax-dell-unisphere-for-powermax-vapp-dell-solutions-enabler-vapp-dell-unisphere-360-dell-vasa-provider-vapp-and-dell-powermax-emb-mgmt-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 5.7
v2 : unknown
v3 : 6.9

21 Jul 2023, 19:05

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-Other

31 May 2023, 06:15

Type Values Removed Values Added
Summary Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized. Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.

Information

Published : 2023-02-13 10:15

Updated : 2024-11-21 07:09


NVD link : CVE-2022-34397

Mitre link : CVE-2022-34397

CVE.ORG link : CVE-2022-34397


JSON object : View

Products Affected

dell

  • evasa_provider_virtual_appliance
  • unisphere_for_powermax_virtual_appliance
  • solutions_enabler_virtual_appliance
CWE
CWE-863

Incorrect Authorization

NVD-CWE-Other