PT-2016-5803 · Dell · Dell Openmanage Server Administrator

Hantwister

·

Published

2016-04-12

·

Updated

2016-12-03

·

CVE-2016-4004

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell OpenManage Server Administrator (OMSA) version 8.2
Description A directory traversal issue allows remote authenticated administrators to read arbitrary files by using a .. (dot dot backslash) in the file parameter to the ViewFile endpoint.
Recommendations For version 8.2, consider restricting access to the ViewFile endpoint until a patch is available. As a temporary workaround, avoid using the file parameter with .. (dot dot backslash) sequences to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4004

Affected Products

Dell Openmanage Server Administrator