Impact
Dell OpenManage Enterprise contains an Improper Restriction of XML External Entity Reference vulnerability. An attacker with low privileges but remote access can supply a crafted XML payload that causes the server to resolve and retrieve data from external XML entities. The flaw permits the server to access arbitrary content from external sources, potentially exposing sensitive information, and is classified as CWE-611.
Affected Systems
Affected deployments are Dell OpenManage Enterprise products with versions prior to 4.7.0. The vulnerability is present in all earlier releases of the software. No other vendors were listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. The EPSS score is <1%, and the vulnerability is not in the CISA KEV catalog. Exploit requires only low privileges and remote access to the web interface; no authentication beyond normal user rights is needed. If an attacker succeeds, the server can retrieve and expose data from arbitrary external resources, potentially revealing confidential system or network information.
OpenCVE Enrichment