Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
Web Parameter Tampering Vulnerability
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation
0
Attacker Value
Unknown
XML External Entity (XXE) Injection Vulnerability
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
0