Dell PowerProtect Data Domain
cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:*:*:*
- >= 7.7.1.0, <= 8.7
- >= 8.6.1.0, <= 8.6.1.10
- >= 8.3.1.0, <= 8.3.1.30
- >= 7.13.1.0, <= 7.13.1.70
A stored cross-site scripting vulnerability has been identified in Dell PowerProtect Data Domain. This issue affects versions 7.7.1.0 prior to 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. The vulnerability allows an unauthenticated attacker with remote access to inject malicious scripts, which could be executed in the context of the user's browser. Exploitation of this vulnerability may lead to information disclosure, session theft, or client-side request forgery.
Exploitation of this vulnerability could result in stored cross-site scripting, allowing injected scripts to be executed in the context of the user.
Users are advised to upgrade to version 8.7.0.0 or later, version 8.8.0.0 or later, or version 7.13.1.80 or later, depending on their current version. For instructions on how to upgrade, see the Dell PowerProtect Data Domain Upgrade Guide.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.