PT-2022-18106 · Dell · Dell Openmanage Enterprise

Bartosz Reginiak

·

Published

2022-05-26

·

Updated

2023-06-28

·

CVE-2022-26857

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell OpenManage Enterprise versions 3.8.3 and prior
Description The issue is related to an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and perform unauthorized actions.
Recommendations For Dell OpenManage Enterprise versions 3.8.3 and prior, update to a version later than 3.8.3 to resolve the issue.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-26857

Affected Products

Dell Openmanage Enterprise