Executive brief
Dell PowerFlex Manager is a management tool used to automate and orchestrate software-defined storage environments. A security flaw in how the system handles database queries could allow a user with low-level access on the local network to inject malicious scripts. This could lead to unauthorized access to sensitive information stored within the management platform.
Technical details
An SQL injection vulnerability (CWE-89) exists in Dell PowerFlex Manager due to improper neutralization of special elements used in SQL commands. An attacker with low privileges and adjacent network access can exploit this flaw to execute arbitrary SQL commands. According to the advisory, this specific injection path can lead to script injection and high-impact information disclosure (Confidentiality: High). The vulnerability is addressed in PowerFlex versions 4.5.5.2 and 5.1.0.1 or later.
Affected products
- Dell PowerFlex Manager Versions prior to 4.5.5.2; versions prior to 5.1.0.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory