« Back to list

CVE-2012-4955

Status: ModifiedMedium (4.3)—

Cross-site scripting (XSS) vulnerability in Dell OpenManage Server Administrator (OMSA) before 6.5.0.1, 7.0 before 7.0.0.1, and 7.1 before 7.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2012-4955",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-11-15T11:58:40.167",
  "references": [
    {
      "url": "http://osvdb.org/87405",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/51297",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.dell.com/support/drivers/us/en/19/DriverDetails/Product/poweredge-r710?driverId=5JDN0&osCode=WNET&fileId=3082293694",
      "tags": [
        "Patch"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.dell.com/support/drivers/us/en/19/DriverDetails/Product/poweredge-r710?driverId=JJMWP&osCode=WNET&fileId=3082295338",
      "tags": [
        "Patch"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.dell.com/support/drivers/us/en/19/DriverDetails/Product/poweredge-r710?driverId=PCXMR&osCode=WNET&fileId=3082295344",
      "tags": [
        "Patch"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/558132",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/56518",
      "source": "cret@cert.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80071",
      "source": "cret@cert.org"
    },
    {
      "url": "http://osvdb.org/87405",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/51297",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.dell.com/support/drivers/us/en/19/DriverDetails/Product/poweredge-r710?driverId=5JDN0&osCode=WNET&fileId=3082293694",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.dell.com/support/drivers/us/en/19/DriverDetails/Product/poweredge-r710?driverId=JJMWP&osCode=WNET&fileId=3082295338",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.dell.com/support/drivers/us/en/19/DriverDetails/Product/poweredge-r710?driverId=PCXMR&osCode=WNET&fileId=3082295344",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/558132",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/56518",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80071",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in Dell OpenManage Server Administrator (OMSA) before 6.5.0.1, 7.0 before 7.0.0.1, and 7.1 before 7.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en Dell OpenManage Server Administrator (OMSA) antes de v6.5.0.1, v7.0 antes de v7.0.0.1 y v7.1 antes de v7.1.0.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:45:57.943",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E706BC8F-630E-4FBC-8FC4-97B87D2EB715",
              "versionEndIncluding": "6.5.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:1.00.0000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6F24610-FB84-4DCC-8844-23A1F0722B9C"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:4.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1912F7A-11BC-43F7-8BED-510EBFFF6864"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:4.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "425AACB0-4516-43F0-83B6-B4C28C7538CE"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:4.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D03DB39C-21E3-4BF4-9B0C-B455BE789A95"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:5.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E1DF0F2-39A4-4BCD-A637-D665224C6857"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:5.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EE1C754-8D05-43C4-841F-845459D133B7"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:5.1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54C118FC-4C80-49C9-804E-866E86C9E713"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:5.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD7B3379-E567-4003-978A-B7807F4546C6"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:5.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C63FD84-0CAE-4617-9B8C-9C41682BA69F"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:5.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4355B597-1FA6-473C-86E6-88B80CA5DE3A"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:5.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E20877CC-F67C-400A-9DBF-4883DA9A8312"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:5.5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F88BE664-1528-4661-A392-F1E2511B569D"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:6.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "624014D2-A5D9-4305-BE2E-8D476C3C0603"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:6.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29E8C581-3B4E-4578-A1EF-DEE26E0F2EE7"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:6.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71B05EC3-489A-45E5-93B9-5D2D9A72B1F1"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:7.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "042FCC01-F649-4AA0-95B1-1FBA63E0D23A"
            },
            {
              "criteria": "cpe:2.3:a:dell:openmanage_server_administrator:7.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AC68FF2-CE6A-4101-A440-022BD2191F68"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}