High severity7.5NVD Advisory· Published Jun 6, 2019· Updated Jun 17, 2026
CVE-2019-3722
CVE-2019-3722
Description
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Range: 9.1.0.3
cpe:2.3:a:dell:emc_openmanage_server_administrator:9.1:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:dell:emc_openmanage_server_administrator:9.1:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_openmanage_server_administrator:9.1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_openmanage_server_administrator:9.1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_openmanage_server_administrator:9.2:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_openmanage_server_administrator:9.2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_openmanage_server_administrator:9.2.0.2:*:*:*:*:*:*:*
- Range: <9.1.0.3, <9.2.0.4
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/108685nvdThird Party Advisory
- www.dell.com/support/article/us/en/04/sln317441/dsa-2019-074-dell-emc-openmanage-server-administrator-multiple-vulnerabilitiesnvdVendor Advisory
News mentions
0No linked articles in our index yet.