VYPR

Openmanage Server Administrator

by Dell

CVEs (39)

  • CVE-2023-43079HigOct 13, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the…

  • CVE-2022-34396HigFeb 1, 2023
    risk 0.46cvss 7.0epss 0.00

    Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system…

  • CVE-2026-81447MedSep 17, 2026
    risk 0.44cvss 6.8epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information…

  • CVE-2026-81453MedSep 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-81443MedSep 17, 2026
    risk 0.42cvss 6.4epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

  • CVE-2026-56794MedAug 7, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

  • CVE-2026-81479MedSep 17, 2026
    risk 0.38cvss 5.8epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2016-4004MedApr 12, 2016
    risk 0.36cvss 4.9epss 0.09

    Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file parameter to ViewFile.

  • CVE-2026-80355MedSep 17, 2026
    risk 0.35cvss 5.4epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

  • CVE-2024-45761MedDec 9, 2024
    risk 0.35cvss 5.4epss 0.00

    Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of…

  • CVE-2021-21514MedMar 2, 2021
    risk 0.32cvss 4.9epss 0.05

    Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote user with admin privileges could potentially exploit this vulnerability to view arbitrary files on the target system by sending a specially crafted URL request.

  • CVE-2019-3720MedApr 25, 2019
    risk 0.32cvss 4.9epss 0.03

    Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exploit this vulnerability to gain unauthorized access to the file system by…

  • CVE-2024-45760MedDec 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.

  • CVE-2026-81441MedSep 17, 2026
    risk 0.26cvss 4.0epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2026-81439LowSep 17, 2026
    risk 0.24cvss 3.7epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

  • CVE-2026-81438LowSep 17, 2026
    risk 0.24cvss 3.7epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2012-6272Jan 25, 2013
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or HTML via the topic parameter to html/index_main.htm in (1) help/sm/en/Output/wwhelp/wwhimpl/js/, (2)…

  • CVE-2013-0740Apr 10, 2014
    risk 0.00cvss —epss 0.01

    Open redirect vulnerability in Dell OpenManage Server Administrator (OMSA) before 7.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the file parameter to HelpViewer.

  • CVE-2012-4955Nov 15, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Dell OpenManage Server Administrator (OMSA) before 6.5.0.1, 7.0 before 7.0.0.1, and 7.1 before 7.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Page 2 of 2