Vulnerabilities > HP

DATE CVE VULNERABILITY TITLE RISK
2020-01-16 CVE-2019-11997 Cross-site Scripting vulnerability in HP Enhanced Internet Usage Manager 8.3/9.0
A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0.
network
low complexity
hp CWE-79
6.1
2020-01-09 CVE-2010-3282 Cleartext Storage of Sensitive Information vulnerability in multiple products
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
local
low complexity
hp redhat fedoraproject CWE-312
3.3
2020-01-09 CVE-2019-6319 Cross-Site Request Forgery (CSRF) vulnerability in HP products
HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.
network
low complexity
hp CWE-352
8.1
2020-01-09 CVE-2019-6332 Cross-site Scripting vulnerability in HP products
A potential security vulnerability has been identified with certain HP InkJet printers.
network
low complexity
hp CWE-79
4.8
2020-01-09 CVE-2019-6331 Information Exposure vulnerability in HP Samsung Mobile Print
An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007.
local
low complexity
hp CWE-200
3.3
2020-01-09 CVE-2019-6330 Unspecified vulnerability in HP Access Control
A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7.
network
low complexity
hp
critical
9.8
2020-01-09 CVE-2019-6320 Cross-Site Request Forgery (CSRF) vulnerability in HP products
Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.
network
low complexity
hp CWE-352
8.1
2020-01-03 CVE-2019-11994 Path Traversal vulnerability in HP products
A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes.
network
low complexity
hp CWE-22
critical
9.8
2020-01-03 CVE-2019-11993 Unspecified vulnerability in HP products
A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes.
network
low complexity
hp
7.5
2019-12-18 CVE-2019-11995 Unspecified vulnerability in HP Universal Internet of Things 1.2.4.0/1.2.4.1/1.2.4.2
Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data.
network
low complexity
hp
7.5