CVE-2023-44284: Dell Apex Protection Storage
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.
Affected products
- Dell Apex Protection Storage: before 6.2.1.110 (fixed in 6.2.1.110); from 7.0, before 7.10.1.15 (fixed in 7.10.1.15)
- Dell Emc Data Domain OS: before 6.2.1.110 (fixed in 6.2.1.110); from 7.0, before 7.12.0.0 (fixed in 7.12.0.0); from 7.7, before 7.7.5.25 (fixed in 7.7.5.25); from 7.10, before 7.10.1.15 (fixed in 7.10.1.15)
- Dell Powerprotect Data Domain: before 6.2.1.110 (fixed in 6.2.1.110); from 7.0, before 7.12.0.0 (fixed in 7.12.0.0)
- Dell Powerprotect Data Domain Management Center: before 6.2.1.110 (fixed in 6.2.1.110); from 7.0, before 7.13.0.10 (fixed in 7.13.0.10); from 7.7, before 7.7.5.25 (fixed in 7.7.5.25); from 7.10, before 7.10.1.15 (fixed in 7.10.1.15)
- Dell Powerprotect Data Protection: before 2.7.6 (fixed in 2.7.6)
Published 2023-12-14. Last modified 2026-06-17.