Impact
A low‑privileged attacker with remote access to Dell OpenManage Enterprise, versions older than 4.7.0, can exploit an Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE‑89). The flaw allows the attacker to inject malicious SQL statements that may retrieve sensitive data from the database, compromising confidentiality.
Affected Systems
Dell OpenManage Enterprise software, version 4.6.x and earlier. Users running these versions are affected regardless of the operating system as the vulnerability resides in the web application component.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, implying no current evidence of active exploitation. The likely attack vector is remote, requiring only low‑privileged credentials or unauthenticated access to the OpenManage Enterprise interface, as indicated in the advisory. An attacker who succeeds can gain unauthorized database access and expose confidential information.
OpenCVE Enrichment