Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product makes files or directories accessible to unauthorized actors, even though they should not be.