Vulnerability Description
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Openmanage Server Administrator | 9.1 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/108685Third Party Advisory
- https://www.dell.com/support/article/us/en/04/sln317441/dsa-2019-074-dell-emc-opVendor Advisory
- http://www.securityfocus.com/bid/108685Third Party Advisory
- https://www.dell.com/support/article/us/en/04/sln317441/dsa-2019-074-dell-emc-opVendor Advisory
FAQ
What is CVE-2019-3722?
CVE-2019-3722 is a vulnerability with a CVSS score of 7.5 (HIGH). Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could pot...
How severe is CVE-2019-3722?
CVE-2019-3722 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3722?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Emc Openmanage Server Administrator.