CVE-2019-3722 is a vulnerability in Dell Emc Openmanage Server Administrator
Published on June 6, 2019
XML External Entity (XXE) Injection Vulnerability
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
Products Associated with CVE-2019-3722
Want to know whenever a new CVE is published for Dell Emc Openmanage Server Administrator? stack.watch will email you.
Affected Versions
Dell EMC OpenManage Server Administrator:- Version 9.1.0.3 and below 9.1.0.3 is affected.
- Version 9.3.0.4 and below 9.3.0.4 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.