PT-2017-16691 · Hewlett Packard · Hpe Intelligent Management Center
Published
2017-03-29
·
Updated
2018-03-15
·
CVE-2017-5797
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HPE Intelligent Management Center (IMC) SOM version v7.3 (E0501)
Description
A Remote Unauthenticated Disclosure of Information issue was discovered, potentially allowing unauthorized access to sensitive information. The vulnerability is related to the FileDownloadServlet in the Service Operation Manager Module, which may disclose the
filePath information.Recommendations
For HPE Intelligent Management Center (IMC) SOM version v7.3 (E0501), consider restricting access to the FileDownloadServlet until a patch is available. As a temporary workaround, avoid using the
filePath parameter in the affected API endpoint to minimize the risk of exploitation.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hpe Intelligent Management Center