PT-2016-5803 · Dell · Dell Openmanage Server Administrator
Hantwister
·
Published
2016-04-12
·
Updated
2016-12-03
·
CVE-2016-4004
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dell OpenManage Server Administrator (OMSA) version 8.2
Description
A directory traversal issue allows remote authenticated administrators to read arbitrary files by using a .. (dot dot backslash) in the
file parameter to the ViewFile endpoint.Recommendations
For version 8.2, consider restricting access to the ViewFile endpoint until a patch is available. As a temporary workaround, avoid using the
file parameter with .. (dot dot backslash) sequences to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Openmanage Server Administrator