CVE-2024-39586

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:emc_appsync:*:*:*:*:*:*:*:*

History

17 Oct 2024, 14:30

Type Values Removed Values Added
First Time Dell emc Appsync
Dell
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:dell:emc_appsync:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000234216/dsa-2024-420-security-update-for-dell-emc-appsync-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000234216/dsa-2024-420-security-update-for-dell-emc-appsync-for-multiple-vulnerabilities - Vendor Advisory

09 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 07:15

Updated : 2024-10-17 14:30


NVD link : CVE-2024-39586

Mitre link : CVE-2024-39586


JSON object : View

Products Affected

dell

  • emc_appsync
CWE
CWE-611

Improper Restriction of XML External Entity Reference