Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configuration setting for the embedded MySQL database.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/105914 | vdb entry third party advisory |
https://www.dell.com/support/article/us/en/04/sln314610/dell-openmanage-network-manager-security-vulnerabilities | mitigation vendor advisory |
https://www.exploit-db.com/exploits/45852/ | mitigation exploit vdb entry third party advisory |