Dell Openmanage Server Administrator vulnerabilities
10 known vulnerabilities affecting dell/openmanage_server_administrator.
Total CVEs
10
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2021-21513P2CRITICALCVSS 9.8fixed in 9.4.0.3≥ 9.5.0.0, < 9.5.0.12021-03-02
CVE-2021-21513 [CRITICAL] CWE-287 CVE-2021-21513: Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Dis
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain admin access on the affected system.
nvd
CVE-2016-4004P3MEDIUMCVSS 4.9PoCv8.22016-04-12
CVE-2016-4004 [MEDIUM] CWE-22 CVE-2016-4004: Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote a
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file parameter to ViewFile.
nvd
CVE-2024-45760P3HIGHCVSS 8.8fixed in 11.1.0.02024-12-09
CVE-2024-45760 [HIGH] CWE-862 CVE-2024-45760: Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access contr
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.
nvd
CVE-2024-45761P3HIGHCVSS 8.1fixed in 11.1.0.02024-12-09
CVE-2024-45761 [HIGH] CWE-20 CVE-2024-45761: Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input valida
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.
nvd
CVE-2022-34396P3HIGHCVSS 7.8≤ 10.3.0.02023-02-01
CVE-2022-34396 [HIGH] CWE-427 CVE-2022-34396: Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection V
Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with elevated privileges. Exploitation may lead to a complete system comprom
nvd
CVE-2024-37130P3HIGHCVSS 7.8≤ 11.0.1.02024-06-11
CVE-2024-37130 [HIGH] CWE-427 CVE-2024-37130: Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escala
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation may lead to a complete system comp
nvd
CVE-2012-6272P4MEDIUMCVSS 4.3PoCv6.5.0.1v7.0.0.1+1 more2013-01-25
CVE-2012-6272 [MEDIUM] CWE-79 CVE-2012-6272: Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1,
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or HTML via the topic parameter to html/index_main.htm in (1) help/sm/en/Output/wwhelp/wwhimpl/js/, (2) help/sm/es/Output/wwhelp/wwhimpl/js/, (3) help/sm/ja/Output/wwhelp/wwhimpl
nvd
CVE-2021-21514P3MEDIUMCVSS 4.9≤ 9.5.02021-03-02
CVE-2021-21514 [MEDIUM] CWE-22 CVE-2021-21514: Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vuln
Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote user with admin privileges could potentially exploit this vulnerability to view arbitrary files on the target system by sending a specially crafted URL request.
nvd
CVE-2013-0740P4MEDIUMCVSS 5.8≤ 7.2.0v7.0.0+3 more2014-04-10
CVE-2013-0740 [MEDIUM] CWE-20 CVE-2013-0740: Open redirect vulnerability in Dell OpenManage Server Administrator (OMSA) before 7.3.0 allows remot
Open redirect vulnerability in Dell OpenManage Server Administrator (OMSA) before 7.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the file parameter to HelpViewer.
nvd
CVE-2012-4955P4MEDIUMCVSS 4.3≤ 6.5.0v1.00.0000+16 more2012-11-15
CVE-2012-4955 [MEDIUM] CWE-79 CVE-2012-4955: Cross-site scripting (XSS) vulnerability in Dell OpenManage Server Administrator (OMSA) before 6.5.0
Cross-site scripting (XSS) vulnerability in Dell OpenManage Server Administrator (OMSA) before 6.5.0.1, 7.0 before 7.0.0.1, and 7.1 before 7.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd