PT-2019-16667 · Dell Emc · Dell Openmanage Server Administrator

Publicado

2019-06-06

·

Atualizado

2019-10-09

·

CVE-2019-3722

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.2.0.4
Description The issue is related to an XML external entity (XXE) injection. A remote unauthenticated attacker could exploit this to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
Recommendations For versions prior to 9.1.0.3, update to version 9.1.0.3 or later. For versions prior to 9.2.0.4, update to version 9.2.0.4 or later.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-3722

Produtos afetados

Dell Openmanage Server Administrator