Impact
Dell OpenManage Enterprise contains an Improper Restriction of XML External Entity Reference vulnerability that allows an attacker to cause the system to resolve and retrieve data from external XML entities. This weakness can expose sensitive information from the server or from networked resources, and is classified as CWE-611.
Affected Systems
Dell OpenManage Enterprise prior to version 4.7.0 is affected. The vulnerability exists in all supported builds before the 4.7.0 release, which includes the older 4.6.x series. Users running those versions should verify that they are in the vulnerable set.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as a moderate risk. No EPSS score is published, and it is not listed in CISA’s KEV catalog. The attack requires low privileges and remote access to the OpenManage Enterprise web interface. The attacker can supply a crafted XML payload that forces the server to retrieve data from an arbitrary external source, potentially exposing confidential data but does not allow execution of code or denial of service.
OpenCVE Enrichment