PT-2016-5803 · Dell · Dell Openmanage Server Administrator
Hantwister
·
Publicado
2016-04-12
·
Atualizado
2016-12-03
·
CVE-2016-4004
CVSS v3.1
4.9
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dell OpenManage Server Administrator (OMSA) version 8.2
Description
A directory traversal issue allows remote authenticated administrators to read arbitrary files by using a .. (dot dot backslash) in the
file parameter to the ViewFile endpoint.Recommendations
For version 8.2, consider restricting access to the ViewFile endpoint until a patch is available. As a temporary workaround, avoid using the
file parameter with .. (dot dot backslash) sequences to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dell Openmanage Server Administrator