Vulnerabilities > EMC > Appsync > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-32458 Improper Access Control vulnerability in EMC Appsync
Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component.
local
low complexity
emc CWE-284
7.8
2017-11-01 CVE-2017-14376 Use of Hard-coded Credentials vulnerability in EMC Appsync 2.0/3.0.0/3.5
EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploited by malicious users to compromise the affected system.
local
low complexity
emc CWE-798
7.2
2017-09-12 CVE-2017-8015 SQL Injection vulnerability in EMC Appsync 2.0/3.0.0
EMC AppSync (all versions prior to 3.5) contains a SQL injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.
network
low complexity
emc CWE-89
7.5