Executive brief
Dell Disk Library for Mainframe is a storage solution used to manage and back up data for mainframe environments. A security vulnerability has been identified that could allow an authorized user with low-level permissions to trick the system into making unauthorized network requests. This could potentially be used to access internal resources or sensitive information that should otherwise be restricted.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Dell Disk Library for Mainframe (DLm) versions 8700 and 2700. The flaw (CWE-918) allows a remote attacker with low-level privileges to submit crafted requests that the server then executes. This can be leveraged to probe internal network services or access metadata and resources that are not directly reachable by the attacker. The vulnerability is present in versions prior to 7.0.1.0. Dell has released version 7.0.1.0 to remediate this issue.
Affected products
- Dell Disk Library for mainframe DLm8700 prior to 7.0.1.0
- Dell Disk Library for mainframe DLm2700 prior to 7.0.1.0
Timeline
- 2026-04-28: disclosed: Initial release of Dell Security Advisory DSA-2026-091
- 2026-04-29: advisory: NVD publication date
- 2026-04-29: patched: Remediation available in version 7.0.1.0 or later