PT-2017-16691 · Hewlett Packard · Hpe Intelligent Management Center
Publicado
2017-03-29
·
Atualizado
2018-03-15
·
CVE-2017-5797
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HPE Intelligent Management Center (IMC) SOM version v7.3 (E0501)
Description
A Remote Unauthenticated Disclosure of Information issue was discovered, potentially allowing unauthorized access to sensitive information. The vulnerability is related to the FileDownloadServlet in the Service Operation Manager Module, which may disclose the
filePath information.Recommendations
For HPE Intelligent Management Center (IMC) SOM version v7.3 (E0501), consider restricting access to the FileDownloadServlet until a patch is available. As a temporary workaround, avoid using the
filePath parameter in the affected API endpoint to minimize the risk of exploitation.Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hpe Intelligent Management Center