Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000216654


DSA-2023-299: Security Update for Dell ESI (Enterprise Storage Integrator) for SAP LAMA multiple security vulnerabilities.

Summary: Dell ESI (Enterprise Storage Integrator) for SAP LAMA remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system. ...

Article Content


Impact

Critical

Details

Proprietary Code CVEs Description  CVSS Base Score CVSS Vector String 
CVE-2023-39245
 
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. 9.8 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-39244 DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an improper access control vulnerability in EHAC component. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unrestricted access to the SOAP APIs. 7.3 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Proprietary Code CVEs Description  CVSS Base Score CVSS Vector String 
CVE-2023-39245
 
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. 9.8 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-39244 DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an improper access control vulnerability in EHAC component. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unrestricted access to the SOAP APIs. 7.3 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Address Product  Affected Versions  Remediated Versions  Link 
 CVE-2023-39244, CVE-2023-39245  ESI (Enterprise Storage Integrator) for SAP LAMA  Versions prior to V10.0.0.0  V11.0.0.1  https://www.dell.com/support/home/en-us/product-support/product/storage-integrator-for-sap-landscape-virtualization-management-/drivers
CVEs Address Product  Affected Versions  Remediated Versions  Link 
 CVE-2023-39244, CVE-2023-39245  ESI (Enterprise Storage Integrator) for SAP LAMA  Versions prior to V10.0.0.0  V11.0.0.1  https://www.dell.com/support/home/en-us/product-support/product/storage-integrator-for-sap-landscape-virtualization-management-/drivers

Workarounds and Mitigations

none

Revision History

Revision DateDescription
1.02023-07-27Initial Release

Related Information


Article Properties


Affected Product

Enterprise Storage Integrator for SAP Landscape Management

Last Published Date

10 Aug 2023

Version

1

Article Type

Dell Security Advisory