Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2024-45761
Disclosure Date: December 09, 2024 (last updated February 05, 2025)
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.
0
Attacker Value
Unknown
CVE-2024-45760
Disclosure Date: December 09, 2024 (last updated February 05, 2025)
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.
0
Attacker Value
Unknown
CVE-2024-37130
Disclosure Date: June 11, 2024 (last updated January 13, 2025)
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation may lead to a complete system compromise.
0
Attacker Value
Unknown
CVE-2023-43079
Disclosure Date: October 13, 2023 (last updated October 21, 2023)
Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the system. Exploitation may lead to a complete system compromise.
0
Attacker Value
Unknown
CVE-2022-34396
Disclosure Date: February 01, 2023 (last updated November 08, 2023)
Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with elevated privileges. Exploitation may lead to a complete system compromise.
0
Attacker Value
Unknown
CVE-2021-21514
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote user with admin privileges could potentially exploit this vulnerability to view arbitrary files on the target system by sending a specially crafted URL request.
0
Attacker Value
Unknown
CVE-2021-21513
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain admin access on the affected system.
0
Attacker Value
Unknown
CVE-2020-5377
Disclosure Date: July 26, 2020 (last updated February 21, 2025)
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit these vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access on the compromised management station.
0
Attacker Value
Unknown
Web Parameter Tampering Vulnerability
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation
0
Attacker Value
Unknown
XML External Entity (XXE) Injection Vulnerability
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
0