Impact
Dell OpenManage Enterprise versions prior to 4.7.0 contain an improper neutralisation of special elements used in SQL commands. The flaw, classified as a classic SQL injection (CWE‑89), allows a low‑privileged attacker with remote access to inject malicious SQL statements. If successful, the attacker can cause the database to execute unintended commands, potentially leading to script injection, thereby compromising confidentiality, integrity and availability of the management system.
Affected Systems
All deployments of Dell OpenManage Enterprise running versions earlier than 4.7.0 are affected. The product is accessed through a web interface and RESTful API; thus, any environment exposing these endpoints to external networks is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1. The EPSS score is 0.0026 (indicating a very low exploitation probability), and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote via the product’s web interface and RESTful API, inferred from the description that a low‑privileged attacker with remote access could exploit the vulnerability. The flaw requires only low‑privileged credentials and could be attempted from outside the protected network if the management interface is reachable.
OpenCVE Enrichment