Openmanage Server Administrator

Vendor:

First CVE: Nov 15, 2012 · Active for 13 years

12
Total CVEs
More Total CVEs than 91% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openmanage Server Administrator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 15, 2012
13 years ago
Most Recent CVE
Dec 9, 2024
596 days ago

CVE Severity & Scoring

Openmanage Server Administrator12 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local2 (16.7%)
Network7 (58.3%)
Unknown3 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High0 (0.0%)
Unknown3 (25.0%)
User Interaction
None9 (75.0%)
Unknown3 (25.0%)
Required0 (0.0%)
Privileges Required
Low4 (33.3%)
High2 (16.7%)
None3 (25.0%)
Unknown3 (25.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypas
Mar 2, 20219.830NONO
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker co
Jun 6, 20199.130NONO
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash
Apr 12, 20164.929NOYES
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or H
Jan 25, 20134.326NOYES
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vu
Dec 9, 20248.824NONO
Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated attacker could potentially ex
Feb 1, 20237.824NONO
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticate
Jun 6, 20197.524NONO
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exp
Dec 9, 20248.123NONO
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user coul
Jun 11, 20247.821NONO
Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote user with admin privileges could potentially exploit this vu
Mar 2, 20214.920NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
16.7% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Openmanage Server Administrator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.214.98.9%01
7.1.0.125.02.0%01
7.1.025.01.8%00
7.0.0.125.02.0%01
7.0.025.01.8%00
6.5.0.114.32.8%01
6.4.014.32.5%00
6.3.014.32.5%00
6.2.014.32.5%00
5.5.0.114.32.5%00
5.5.014.32.5%00
5.4.014.32.5%00
5.3.014.32.5%00
5.2.014.32.5%00
5.1.0.114.32.5%00
5.1.014.32.5%00
5.0.014.32.5%00
4.5.014.32.5%00
4.4.014.32.5%00
4.3.014.32.5%00