Database/Control plane, storage & DevOps
Dell OpenManage Enterprise (path traversal): An unauthenticated remote attacker reads files from the OME server
CVSS 5.7CVE-2024-25944Control plane, storage & DevOpscurated
Impact
An unauthenticated remote attacker reads files from the OME server filesystem with the web application's privileges.
Who can reach it
Unauthenticated network access to the OME web interface (v4.0 and prior).
What to do
Apply the DSA-2024-100 update. Application upgrade. OME should never be internet-reachable; verify that while patching.
References
Related entries
- Elastic Metricbeat: oversized Prometheus remote_write request drives an unbounded allocation and kills the beatCVE-2026-26931 · Elastic Metricbeat (Prometheus remote_write HTTP handler)Medium
- AMD Zen 1 / Zen 2 / Zen 3 - execution unit scheduler queue contention (SMT): AMD's split scheduler design gives eachCVE-2021-46778 · AMD Zen 1 / Zen 2 / Zen 3 - execution unit scheduler queue contention (SMT)Medium
- IBM Spectrum Scale / GPFS node file access path: An unprivileged but authenticated user on a GPFS node reads arbitraryCVE-2018-1723 · IBM Spectrum Scale / GPFS node file access pathMedium
- IBM GPFS command line utility: Any unprivileged user with a shell on a GPFS node can force GPFS down on that nodeCVE-2018-1783 · IBM GPFS command line utilityMedium
- Slurm (slurmdbd.conf file permissions): slurmdbd.conf is installed world-readable, which leaks the accountingCVE-2019-19727 · Slurm (slurmdbd.conf file permissions)Medium
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (improper input validation) reachableCVE-2020-24502 · Intel E810 adapter driver for Linux (< 1.0.4)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.