PT-2020-9232 · Hewlett Packard · Hpe Superdome Flex Server
Published
2020-01-16
·
Updated
2020-01-29
·
CVE-2019-11998
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HPE Superdome Flex Server versions prior to v3.20.206
Description
The issue is related to improper input validation of administrator commands, which could allow an administrator to bypass security restrictions. This may lead to information disclosure or denial of service.
Recommendations
Apply firmware version v3.20.206 (released on 4 December 2019) or a newer version to resolve this issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hpe Superdome Flex Server