4 results (0.002 seconds)

CVSS: 8.1EPSS: 0%CPEs: 2EXPL: 0

Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to gain access to sensitive information or cause denial-of-service. Dell EMC OpenManage Enterprise (OME) versiones anteriores a 3.2 y OpenManage Enterprise-Modular (OME-M) versiones anteriores a 1.10.00, contiene una vulnerabilidad de inyección. Un usuario malicioso autenticado remoto y con pocos privilegios podría potencialmente explotar esta vulnerabilidad para conseguir acceso a información confidencial o causar una denegación de servicio • https://www.dell.com/support/kbdoc/en-us/000176929/dsa-2020-023-dell-emc-openmanage-enterprise-enterprise-modular-multiple-vulnerabilities • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit the vulnerability to execute arbitrary shell commands on the affected system. Dell EMC OpenManage Enterprise-Modular (OME-M) versiones anteriores a 1.10.00, contiene una vulnerabilidad de inyección de comandos. Un usuario malicioso autenticado remoto con altos privilegios podría potencialmente explotar la vulnerabilidad para ejecutar comandos shell arbitrario en el sistema afectado • https://www.dell.com/support/kbdoc/en-us/000176929/dsa-2020-023-dell-emc-openmanage-enterprise-enterprise-modular-multiple-vulnerabilities • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 7.6EPSS: 0%CPEs: 2EXPL: 0

Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an improper input validation vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to spawn tasks with elevated privileges. Dell EMC OpenManage Enterprise (OME) versiones anteriores a 3.2 y OpenManage Enterprise-Modular (OME-M) versiones anteriores a 1.10.00, contiene una vulnerabilidad de comprobación inapropiada de entrada. Un usuario malicioso autenticado remoto con privilegios elevados podría potencialmente explotar esta vulnerabilidad para generar tareas con privilegios elevados • https://www.dell.com/support/kbdoc/en-us/000176929/dsa-2020-023-dell-emc-openmanage-enterprise-enterprise-modular-multiple-vulnerabilities • CWE-20: Improper Input Validation •

CVSS: 9.0EPSS: 0%CPEs: 2EXPL: 0

Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a SQL injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions. Dell EMC OpenManage Enterprise (OME) versiones anteriores a 3.2 y las versiones de OpenManage Enterprise-Modular (OME-M) versiones anteriores a 1.10.00, contiene una vulnerabilidad de inyección SQL. Un usuario malicioso autenticado remoto y con privilegios elevados podría potencialmente explotar esta vulnerabilidad para ejecutar comandos SQL y llevar a cabo acciones no autorizadas • https://www.dell.com/support/kbdoc/en-us/000176929/dsa-2020-023-dell-emc-openmanage-enterprise-enterprise-modular-multiple-vulnerabilities • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •