DSA-2024-481: Security Update for Dell OpenManage Server Administrator (OMSA) Vulnerabilities

Zusammenfassung: Dell OpenManage Server Administrator (OMSA) remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Auswirkungen

Medium

Details

Proprietary Code CVE

Description

CVSS Base Score

CVSS Vector String

CVE-2024-45760

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.

4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-45761

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.

5.4

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVE

Description

CVSS Base Score

CVSS Vector String

CVE-2024-45760

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.

4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-45761

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.

5.4

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies empfiehlt allen Kunden, sowohl die CVSS-Gesamtbewertung als auch alle relevanten zeitlichen und umweltbezogenen Bewertungen zu berücksichtigen, die sich auf den potenziellen Schweregrad einer bestimmten Sicherheitsschwachstelle auswirken können.

Betroffene Produkte und Korrektur

Product

Affected Versions

Remediated Versions

Link

Dell OpenManage Server Administrator Managed Node for Windows

Version 11.0.1.0 and prior

11.1.0.0

https://www.dell.com/support/home/drivers/DriversDetails?driverid=W3318

Dell OpenManage Server Administrator Managed Node (Linux Consolidated)

Version 11.0.1.0 and prior

11.1.0.0

https://www.dell.com/support/home/drivers/driversdetails?driverId=30R6G

Dell Systems Management Tools and Documentation DVD ISO

Version 11.0.1.0 and prior

11.1.0.0

https://www.dell.com/support/home/drivers/driversdetails?driverId=PW8WM

Product

Affected Versions

Remediated Versions

Link

Dell OpenManage Server Administrator Managed Node for Windows

Version 11.0.1.0 and prior

11.1.0.0

https://www.dell.com/support/home/drivers/DriversDetails?driverid=W3318

Dell OpenManage Server Administrator Managed Node (Linux Consolidated)

Version 11.0.1.0 and prior

11.1.0.0

https://www.dell.com/support/home/drivers/driversdetails?driverId=30R6G

Dell Systems Management Tools and Documentation DVD ISO

Version 11.0.1.0 and prior

11.1.0.0

https://www.dell.com/support/home/drivers/driversdetails?driverId=PW8WM

Revisionsverlauf

Revision

Date

Description

1.0

2024-12-09

Initial Release

2.0

2025-04-29

Fixed broken link for Dell OpenManage Server Administrator Managed Node for Windows 

Zugehörige Informationen

Betroffene Produkte

OpenManage Server Administrator
Artikeleigenschaften
Artikelnummer: 000258320
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 29 Apr. 2025
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.