Unrated severityNVD Advisory· Published Jun 6, 2019· Updated Sep 16, 2024
XML External Entity (XXE) Injection Vulnerability
CVE-2019-3722
Description
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
Affected products
1- Range: 9.1.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/108685mitrevdb-entryx_refsource_BID
- www.dell.com/support/article/us/en/04/sln317441/dsa-2019-074-dell-emc-openmanage-server-administrator-multiple-vulnerabilitiesmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.