First published: Fri Nov 30 2018(Updated: )
Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configuration setting for the embedded MySQL database.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell OpenManage | <6.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15768 is considered to be of medium severity due to the risk of unauthorized read/write access to the file system.
To fix CVE-2018-15768, upgrade Dell OpenManage Network Manager to version 6.5.0 or later.
CVE-2018-15768 is caused by insecure default configurations allowing unnecessary permissions for MySQL users.
All versions of Dell OpenManage Network Manager prior to 6.5.0 are affected by CVE-2018-15768.
CVE-2018-15768 allows MySQL users to gain unauthorized read/write access to the file system, potentially leading to data breaches.