DSA-2023-299: Security Update for Dell ESI (Enterprise Storage Integrator) for SAP LAMA multiple security vulnerabilities.

Summary: Dell ESI (Enterprise Storage Integrator) for SAP LAMA remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

Proprietary Code CVEs Description  CVSS Base Score CVSS Vector String 
CVE-2023-39245
 
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. 9.8 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-39244 DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an improper access control vulnerability in EHAC component. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unrestricted access to the SOAP APIs. 7.3 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Proprietary Code CVEs Description  CVSS Base Score CVSS Vector String 
CVE-2023-39245
 
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. 9.8 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-39244 DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an improper access control vulnerability in EHAC component. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unrestricted access to the SOAP APIs. 7.3 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs Address Product  Affected Versions  Remediated Versions  Link 
 CVE-2023-39244, CVE-2023-39245  ESI (Enterprise Storage Integrator) for SAP LAMA  Versions prior to V10.0.0.0  V11.0.0.1  https://www.dell.com/support/home/en-us/product-support/product/storage-integrator-for-sap-landscape-virtualization-management-/drivers
CVEs Address Product  Affected Versions  Remediated Versions  Link 
 CVE-2023-39244, CVE-2023-39245  ESI (Enterprise Storage Integrator) for SAP LAMA  Versions prior to V10.0.0.0  V11.0.0.1  https://www.dell.com/support/home/en-us/product-support/product/storage-integrator-for-sap-landscape-virtualization-management-/drivers

Workarounds & Mitigations

none

Revision History

Revision DateDescription
1.02023-07-27Initial Release

Related Information

Affected Products

Enterprise Storage Integrator for SAP Landscape Management
Article Properties
Article Number: 000216654
Article Type: Dell Security Advisory
Last Modified: 10 Aug 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.