Vulnerabilities > HP

DATE CVE VULNERABILITY TITLE RISK
2020-12-02 CVE-2020-7199 Improper Authentication vulnerability in HP Edgeline Infrastructure Manager
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software.
network
low complexity
hp CWE-287
critical
9.8
2020-11-06 CVE-2020-7198 Unspecified vulnerability in HP Oneview, Synergy Composer and Synergy Composer 2
There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer.
network
low complexity
hp
8.8
2020-11-05 CVE-2020-7207 Unspecified vulnerability in HP products
A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE).
low complexity
hp
6.8
2020-10-26 CVE-2020-7197 Improper Authentication vulnerability in HP Storeserv Management Console 3.4/3.4.1/3.5.0
SSMC3.7.0.0 is vulnerable to remote authentication bypass.
network
low complexity
hp CWE-287
critical
9.8
2020-10-26 CVE-2020-7196 Insufficiently Protected Credentials vulnerability in HP Bluedata Epic and Ezmeral Container Platform
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval.
network
low complexity
hp CWE-522
6.5
2020-10-22 CVE-2020-11853 Arbitrary code execution vulnerability affecting multiple Micro Focus products.
network
low complexity
microfocus hp
8.8
2020-10-19 CVE-2020-7195 Expression Language Injection vulnerability in HP Intelligent Management Center
A iccselectrules expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
network
low complexity
hp CWE-917
8.8
2020-10-19 CVE-2020-7194 Expression Language Injection vulnerability in HP Intelligent Management Center
A perfaddormoddevicemonitor expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
network
low complexity
hp CWE-917
8.8
2020-10-19 CVE-2020-7193 Expression Language Injection vulnerability in HP Intelligent Management Center
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
network
low complexity
hp CWE-917
8.8
2020-10-19 CVE-2020-7192 Expression Language Injection vulnerability in HP Intelligent Management Center
A devicethresholdconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
network
low complexity
hp CWE-917
8.8