HTTP: Dell ScriptLogic Asset Manager GetProcessedPackage SQL Injection

This signature detects attempts to exploit a known vulnerability against Dell ScriptLogic Asset Manager. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Multiple SQL injection vulnerabilities in Dell ScriptLogic Asset Manager (aka Quest Workspace Asset Manager) before 9.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) GetClientPackage.aspx or (2) GetProcessedPackage.aspx.

Affected Products

Dell asset_manager

Short Name
HTTP:SQL:INJ:DELL-SL-ASST-MNGR
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Asset CVE-2015-1605 Dell GetProcessedPackage Injection Manager SQL ScriptLogic
Release Date
04/08/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3797
False Positive
Unknown
Vendors

Dell

Found a potential security threat?