Database/Control plane, storage & DevOps
Dell OpenManage Enterprise (path traversal): An unauthenticated remote attacker reads files from the OME server
CVE-2024-25944Control plane, storage & DevOpscurated
Impact
An unauthenticated remote attacker reads files from the OME server filesystem with the web application's privileges.
Who can reach it
Unauthenticated network access to the OME web interface (v4.0 and prior).
What to do
Apply the DSA-2024-100 update. Application upgrade. OME should never be internet-reachable; verify that while patching.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.