Dell PowerProtect Data Manager Improper Output Encoding Vulnerability in Reporting Component

Vulnerability

A vulnerability has been identified in the Dell PowerProtect Data Manager Reporting component, specifically in versions 19.17 and 19.18. This vulnerability involves improper encoding or escaping of output, which could allow a high-privileged attacker with local access to inject arbitrary web scripts or HTML into reporting outputs.

Impact

Exploitation of this vulnerability could lead to the injection of malicious web scripts or HTML, potentially allowing for cross-site scripting attacks or manipulation of the reporting output.

Remediation

Users can upgrade to Dell PowerProtect Data Manager version 19.19.0-15 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.3
exploitability
3.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.