CVE-2019-3722: Dell Emc Openmanage Server Administrator

High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.

Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.

Affected products

  • Dell Emc Openmanage Server Administrator: version 9.1 only; version 9.1.0.1 only; version 9.1.0.2 only; version 9.2 only; version 9.2.0.1 only; version 9.2.0.2 only

Published 2019-06-06. Last modified 2026-06-17.