CVE-2018-11048
Summary
| CVE | CVE-2018-11048 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-10 20:29:00 UTC |
| Updated | 2020-12-08 17:08:00 UTC |
| Description | Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain system files in the server or cause denial of service by supplying specially crafted Document Type Definitions (DTDs) in an XML request. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Emc Data Protection Advisor | 6.2 | All | All | All |
| Application | Dell | Emc Data Protection Advisor | 6.3 | All | All | All |
| Application | Dell | Emc Data Protection Advisor | 6.4 | All | All | All |
| Application | Dell | Emc Data Protection Advisor | 6.5 | All | All | All |
| Application | Dell | Emc Data Protection Advisor | 6.2 | All | All | All |
| Application | Dell | Emc Data Protection Advisor | 6.3 | All | All | All |
| Application | Dell | Emc Data Protection Advisor | 6.4 | All | All | All |
| Application | Dell | Emc Data Protection Advisor | 6.5 | All | All | All |
| Application | Dell | Emc Integrated Data Protection Appliance | 2.0 | All | All | All |
| Application | Dell | Emc Integrated Data Protection Appliance | 2.1 | All | All | All |
| Application | Dell | Emc Integrated Data Protection Appliance | 2.0 | All | All | All |
| Application | Dell | Emc Integrated Data Protection Appliance | 2.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: DSA-2018-112: Dell EMC Data Protection Advisor XML External Entity Vulnerability | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| EMC Data Protection Advisor XML External Entity Processing Flaw Lets Remote Authenticated Users Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| EMC Data Protection Advisor CVE-2018-11048 XML External Entity Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.