CVE-2024-39586

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:emc_appsync:*:*:*:*:*:*:*:*

History

17 Oct 2024, 14:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 2.9
v2 : unknown
v3 : 4.3
First Time Dell
Dell emc Appsync
References () https://www.dell.com/support/kbdoc/en-us/000234216/dsa-2024-420-security-update-for-dell-emc-appsync-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000234216/dsa-2024-420-security-update-for-dell-emc-appsync-for-multiple-vulnerabilities - Vendor Advisory
CPE cpe:2.3:a:dell:emc_appsync:*:*:*:*:*:*:*:*

10 Oct 2024, 12:51

Type Values Removed Values Added
Summary
  • (es) Dell AppSync Server, versión 4.3 a 4.6, contiene una vulnerabilidad de inyección de entidad externa XML. Un atacante adyacente con privilegios elevados podría aprovechar esta vulnerabilidad, lo que daría lugar a la divulgación de información.

09 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 07:15

Updated : 2024-10-17 14:30


NVD link : CVE-2024-39586

Mitre link : CVE-2024-39586

CVE.ORG link : CVE-2024-39586


JSON object : View

Products Affected

dell

  • emc_appsync
CWE
CWE-611

Improper Restriction of XML External Entity Reference