CVE Published: 25/10/2024 |
CVE Updated: 25/10/2024 |
CVE Year: 2024 Source: dell |
Vendor: Dell |
Product: Data Lakehouse Status : PUBLISHED
CVE-2024-47483 Description
Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Metrics
CVSS Version: 3.1 |
Base Score: 2.9 LOW Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* NONE User Interaction (UI)* NONE Scope (S)* UNCHANGED