Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
https://www.dell.com/support/kbdoc/en-us/000234216/dsa-2024-420-security-update-for-dell-emc-appsync-for-multiple-vulnerabilities
Source: Mitre, NVD
Published: 2024-10-09
Updated: 2024-10-17
Base Score: 5
Vector: CVSS2#AV:A/AC:L/Au:M/C:C/I:N/A:N
Severity: Medium
Base Score: 4.3
Vector: CVSS:3.0/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
EPSS: 0.00053