Home
LOW: 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
Any version before 9.2.4.15
affected
Any version before 10.2.0.9
affected
Description
Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Problem types
CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
Product status
Any version before 9.2.4.15
Any version before 10.2.0.9
References
www.dell.com/...security-update-for-multiple-vulnerabilities