Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hprw-3fgf-8j27

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Dell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to overwrite arbitrary files via directory traversal sequences using a crafted tar file to inject malicious RPMs which may cause a denial of service or perform unauthorized actions.

Dell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to overwrite arbitrary files via directory traversal sequences using a crafted tar file to inject malicious RPMs which may cause a denial of service or perform unauthorized actions.

EPSS

Процентиль: 78%
0.01143
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.9
nvd
больше 4 лет назад

Dell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to overwrite arbitrary files via directory traversal sequences using a crafted tar file to inject malicious RPMs which may cause a denial of service or perform unauthorized actions.

EPSS

Процентиль: 78%
0.01143
Низкий

Дефекты

CWE-22