Executive brief
Dell PowerFlex Manager is a tool used to manage and automate software-defined storage environments. A security flaw allows a user with low-level access to perform unauthorized database queries, which could lead to the exposure of sensitive system information. This could compromise the privacy of the data managed by the platform or provide insights that help an attacker plan further activities.
Technical details
An SQL injection vulnerability (CWE-89) exists in Dell PowerFlex Manager due to improper neutralization of special elements used in SQL commands. A remote attacker with low-level privileges can exploit this flaw by submitting malicious SQL queries to the application. Successful exploitation can lead to unauthorized information exposure from the underlying database. The vulnerability is addressed in PowerFlex Manager versions 5.1.0.1 and 4.5.5.2.
Affected products
- Dell PowerFlex Manager prior to 5.1.0.1, prior to 4.5.5.2
Timeline
- 2026-07-10: advisory
- 2026-07-10: disclosed