CVE-2019-3723: Web Parameter Tampering Vulnerability
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dell EMC OpenManage Server Administrator vulnerability?
The vulnerability ID for this Dell EMC OpenManage Server Administrator vulnerability is CVE-2019-3723.
What is the severity rating of the CVE-2019-3723 vulnerability?
The severity rating of the CVE-2019-3723 vulnerability is critical (9.1).
What is the affected software version range for the CVE-2019-3723 vulnerability?
The affected software version range for the CVE-2019-3723 vulnerability is versions prior to 9.1.0.3 and prior to 9.2.0.4 of Dell EMC OpenManage Server Administrator (OMSA).
What is the impact of the CVE-2019-3723 vulnerability?
The impact of the CVE-2019-3723 vulnerability is that a remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete files.
How can I fix the CVE-2019-3723 vulnerability?
To fix the CVE-2019-3723 vulnerability, it is recommended to update Dell EMC OpenManage Server Administrator to version 9.1.0.3 or version 9.2.0.4 or later.