CVE-2023-39244

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:enterprise_storage_integrator_for_sap_landscape_management:*:*:*:*:*:*:*:*

History

23 Jan 2025, 16:57

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Dell enterprise Storage Integrator For Sap Landscape Management
Dell
References () https://www.dell.com/support/kbdoc/en-us/000216654/dsa-2023-299-security-update-for-dell-esi-enterprise-storage-integrator-for-sap-lama-multiple-security-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000216654/dsa-2023-299-security-update-for-dell-esi-enterprise-storage-integrator-for-sap-lama-multiple-security-vulnerabilities - Vendor Advisory
CPE cpe:2.3:a:dell:enterprise_storage_integrator_for_sap_landscape_management:*:*:*:*:*:*:*:*

21 Nov 2024, 08:14

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000216654/dsa-2023-299-security-update-for-dell-esi-enterprise-storage-integrator-for-sap-lama-multiple-security-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000216654/dsa-2023-299-security-update-for-dell-esi-enterprise-storage-integrator-for-sap-lama-multiple-security-vulnerabilities -

20 Feb 2024, 14:15

Type Values Removed Values Added
Summary DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an improper access control vulnerability in EHAC component. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unrestricted access to the SOAP APIs. DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.

15 Feb 2024, 14:28

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-15 13:15

Updated : 2025-01-23 16:57


NVD link : CVE-2023-39244

Mitre link : CVE-2023-39244

CVE.ORG link : CVE-2023-39244


JSON object : View

Products Affected

dell

  • enterprise_storage_integrator_for_sap_landscape_management
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo