CVE-2024-39586 - CERT CVE
ID CVE-2024-39586
Sažetak Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
Reference
CVSS
Base: 4.3
Impact: 3.6
Exploitability:0.7
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH NONE NONE
CVSS vektor CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Zadnje važnije ažuriranje 17-10-2024 - 14:30
Objavljeno 09-10-2024 - 07:15