Server-Side Template Injection in Dell EMC Data Protection Advisor Products
CVE-2019-18582
9.1CRITICAL
Summary
The server-side template injection vulnerability in Dell EMC Data Protection Advisor's REST API allows a remote authenticated user with administrative privileges to inject malicious scripts. This exploitation could lead to OS command execution, as the DPA service operates under the context of a regular user on the affected system. Patch updates are critical to mitigating this risk.
Affected Version(s)
Data Protection Advisor < 6.3, 6.4, 6.5 and version prior to 18.2 patch 83 and prior to 19.1 patch 71
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved