First published: Thu Jun 06 2019(Updated: )
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC OpenManage Server Administrator | =9.1 | |
Dell EMC OpenManage Server Administrator | =9.1.0.1 | |
Dell EMC OpenManage Server Administrator | =9.1.0.2 | |
Dell EMC OpenManage Server Administrator | =9.2 | |
Dell EMC OpenManage Server Administrator | =9.2.0.1 | |
Dell EMC OpenManage Server Administrator | =9.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dell EMC OpenManage Server Administrator vulnerability is CVE-2019-3723.
The severity rating of the CVE-2019-3723 vulnerability is critical (9.1).
The affected software version range for the CVE-2019-3723 vulnerability is versions prior to 9.1.0.3 and prior to 9.2.0.4 of Dell EMC OpenManage Server Administrator (OMSA).
The impact of the CVE-2019-3723 vulnerability is that a remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete files.
To fix the CVE-2019-3723 vulnerability, it is recommended to update Dell EMC OpenManage Server Administrator to version 9.1.0.3 or version 9.2.0.4 or later.