DSA-2019-074: Dell EMC OpenManage Server Administrator Multiple Vulnerabilities-DSA

Resumo: Dell EMC Open Manage Server Administrator has been updated to address multiple vulnerabilities which may be potentially exploited to compromise the system.

Este artigo aplica-se a Este artigo não se aplica a Este artigo não está vinculado a nenhum produto específico. Nem todas as versões do produto estão identificadas neste artigo.

Impacto

Critical

Dados

  • XML External Entity (XXE) Injection Vulnerability (CVE-2019-3722)
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
           
             CVSSv3 Base Score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
  • Web Parameter Tampering Vulnerability (CVE-2019-3723)
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation.
           
             CVSSv3 Base Score 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
  • XML External Entity (XXE) Injection Vulnerability (CVE-2019-3722)
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
           
             CVSSv3 Base Score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
  • Web Parameter Tampering Vulnerability (CVE-2019-3723)
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation.
           
             CVSSv3 Base Score 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
A Dell Technologies recomenda que todos os clientes levem em consideração a pontuação base CVSS e as pontuações temporais e ambientais pertinentes que possam afetar a gravidade potencial associada a uma vulnerabilidade de segurança específica.

Produtos afetados e soluções

Affected products:
  • Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3
  • Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.2.0.4 
Remediation:      
The following Dell EMC OpenManage Server Administrator releases contain resolutions to these vulnerabilities:
  • Dell EMC OpenManage Server Administrator 9.1.0.3 and later
  • Dell EMC OpenManage Server Administrator 9.2.0.4 and later
  • Dell EMC OpenManage Server Administrator 9.3.0 and later
Dell EMC recommends all customers upgrade at the earliest opportunity.  

Customers can download OpenManage Server Administrator for PowerEdge servers. For all other platforms, please select the platform from the Dell support site.
Affected products:
  • Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3
  • Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.2.0.4 
Remediation:      
The following Dell EMC OpenManage Server Administrator releases contain resolutions to these vulnerabilities:
  • Dell EMC OpenManage Server Administrator 9.1.0.3 and later
  • Dell EMC OpenManage Server Administrator 9.2.0.4 and later
  • Dell EMC OpenManage Server Administrator 9.3.0 and later
Dell EMC recommends all customers upgrade at the earliest opportunity.  

Customers can download OpenManage Server Administrator for PowerEdge servers. For all other platforms, please select the platform from the Dell support site.

Informações relacionadas

Produtos afetados

Dell OpenManage Server Administrator Version 8.4, Dell OpenManage Server Administrator Version 8.5, Dell OpenManage Server Administrator Version 9.0.1, Dell OpenManage Server Administrator Version 9.0.2 , Dell OpenManage Server Administrator Version 9.1, Dell OpenManage Server Administrator Version 8.3, Dell OpenManage Server Administrator Version 6.5 A02, Dell OpenManage Server Administrator Version 7.0, Dell OpenManage Server Administrator Version 7.1, Dell OpenManage Server Administrator Version 7.2, Dell OpenManage Server Administrator Version 7.3, Dell OpenManage Server Administrator Version 7.4, Dell OpenManage Server Administrator Version 8.0.1, Dell OpenManage Server Administrator Version 8.0.2, Dell OpenManage Server Administrator Version 8.1, Dell OpenManage Server Administrator Version 8.2, Dell OpenManage Server Administrator Version 9.1.1, Dell OpenManage Server Administrator Version 9.1.2, Dell OpenManage Server Administrator Version 9.2, Product Security Information ...
Propriedades do artigo
Número do artigo: 000180635
Tipo de artigo: Dell Security Advisory
Último modificado: 19 set. 2025
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.