cbcvebase.

Dell Openmanage Enterprise vulnerabilities

24 known vulnerabilities affecting dell/openmanage_enterprise.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM9

Vulnerabilities

Page 2 of 2
CVE-2021-21584P3MEDIUMCVSS 6.5v3.52021-08-09
CVE-2021-21584 [MEDIUM] CWE-200 CVE-2021-21584: Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenticated low privileged attacker may potentially exploit this vulnerability leading to disclosure of the OIDC server credentials.
nvd
CVE-2020-5370P4MEDIUMCVSS 6.8≥ unspecified, < 3.42021-07-22
CVE-2020-5370 [MEDIUM] CWE-22 CVE-2020-5370: Dell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulne Dell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to overwrite arbitrary files via directory traversal sequences using a crafted tar file to inject malicious RPMs which may cause a denial of
nvd
CVE-2026-54793P4MEDIUMCVSS 5.4fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-54793 [MEDIUM] CWE-79 CVE-2026-54793: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input Du Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
nvd
CVE-2024-28979P4MEDIUMCVSS 4.8fixed in 4.1.02024-05-01
CVE-2024-28979 [MEDIUM] CWE-79 CVE-2024-28979: Dell OpenManage Enterprise, versions 4.1.0 and older, contains an Improper Neutralization of Input D Dell OpenManage Enterprise, versions 4.1.0 and older, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
nvd
Dell Openmanage Enterprise vulnerabilities | cvebase