PT-2022-4183 · Hewlett Packard · Hpe Oneview

Nikita Abramov

·

Published

2022-01-17

·

Updated

2023-08-08

·

CVE-2022-23700

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HPE OneView versions prior to 6.6
Description The issue is related to authentication errors in the HPE OneView IT infrastructure management system. Exploitation of this issue may allow an attacker to gain unauthorized access to protected information. A local unauthorized read access to files vulnerability was discovered, which can be resolved with a software update provided by HPE.
Recommendations For HPE OneView versions prior to 6.6, update to version 6.6 or later to resolve the vulnerability. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2022-05031
CVE-2022-23700

Affected Products

Hpe Oneview