CVE-2019-3723
Summary
| CVE | CVE-2019-3723 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-06 19:29:00 UTC |
| Updated | 2019-10-09 23:49:00 UTC |
| Description | Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Emc Openmanage Server Administrator | 9.1 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.1.0.1 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.1.0.2 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.2 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.2.0.1 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.2.0.2 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.1 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.1.0.1 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.1.0.2 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.2 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.2.0.1 | All | All | All |
| Application | Dell | Emc Openmanage Server Administrator | 9.2.0.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2019-074: Dell EMC OpenManage Server Administrator Multiple Vulnerabilities | Dell India | CONFIRM | www.dell.com | Vendor Advisory |
| Dell EMC OpenManage Server Administrator Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.