Article Number: 000200215
Medium
Proprietary Code CVE(s) |
Description |
CVSS Base Score |
CVSS Vector String |
CVE-2022-29096 |
Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigurations page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery. |
6.1 |
|
CVE-2022-29097 |
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. |
4.9 |
Third-Party Component |
CVE(s) |
More information |
JQuery UI Library |
CVE-2021-41184 |
See NVD for individual scores for each CVE |
Proprietary Code CVE(s) |
Description |
CVSS Base Score |
CVSS Vector String |
CVE-2022-29096 |
Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigurations page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery. |
6.1 |
|
CVE-2022-29097 |
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. |
4.9 |
Third-Party Component |
CVE(s) |
More information |
JQuery UI Library |
CVE-2021-41184 |
See NVD for individual scores for each CVE |
Product |
Affected Version(s) |
Updated Version(s) |
Link to Update |
Dell Wyse Management Suite |
3.6.1 and below |
3.7 |
|
Product |
Affected Version(s) |
Updated Version(s) |
Link to Update |
Dell Wyse Management Suite |
3.6.1 and below |
3.7 |
|
None
CVE-2022-29097: Dell Technologies would like to thank bugbounty2k20 for reporting this issue.
Revision |
Date |
Description |
1.0 |
2022-05-31 |
Initial Release |
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Product Security Information, Wyse Management Suite
01 Jun 2022
2
Dell Security Advisory