DSA-2020-277: Dell EMC Unisphere PowerMax Cross-Site Scripting (XSS) Vulnerability

요약: Dell EMC Unisphere PowerMax contains remediation for a Cross-Site Scripting (XSS) Vulnerability that could be exploited by malicious users to compromise the affected system.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

Medium

세부 정보

Proprietary Code CVE(s) Description CVSSBase Score CVSS Vector String
CVE-2020-35170
 
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.24 contain a Stored Cross-Site Scripting vulnerability. A remote, authenticated attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Proprietary Code CVE(s) Description CVSSBase Score CVSS Vector String
CVE-2020-35170
 
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.24 contain a Stored Cross-Site Scripting vulnerability. A remote, authenticated attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

Product Affected Version(s) Updated Version(s) Link to Update
Unisphere for PowerMax Versions prior to 9.1.0.24 9.1.0.24

EEM: 9.1.0.853
https://www.dell.com/support/home/en-us/product-support/product/unisphere-powermax/drivers
Unisphere for PowerMax Versions prior to 9.2.0.6 9.2.0.6

EEM: 9.2.0.1018
https://www.dell.com/support/home/en-us/product-support/product/unisphere-powermax/drivers
PowerMax OS 5978 5978 Request OPT 577141

Request OPT 576388
Product Affected Version(s) Updated Version(s) Link to Update
Unisphere for PowerMax Versions prior to 9.1.0.24 9.1.0.24

EEM: 9.1.0.853
https://www.dell.com/support/home/en-us/product-support/product/unisphere-powermax/drivers
Unisphere for PowerMax Versions prior to 9.2.0.6 9.2.0.6

EEM: 9.2.0.1018
https://www.dell.com/support/home/en-us/product-support/product/unisphere-powermax/drivers
PowerMax OS 5978 5978 Request OPT 577141

Request OPT 576388

해결 방법 및 완화 방안

Any chart or dashboard with stored cross-site scripting needs to be deleted to remove the stored XSS.

개정 내역

RevisionDateDescription
1.02020-12-14Initial Release

감사의 말

Dell would like to thank Tomasz Stachowicz and Przemek Nowakowski for reporting this issue.

관련 정보

해당 제품

PowerMaxOS 5978, Unisphere for PowerMax
문서 속성
문서 번호: 000181212
문서 유형: Dell Security Advisory
마지막 수정 시간: 17 12월 2020
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.