6 results (0.002 seconds)

CVSS: 9.8EPSS: 15%CPEs: 1EXPL: 0

31 Aug 2017 — A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely. Una vulnerabilidad de validación de entradas en el producto HPE Operations Orchestration en todas las versiones anteriores a 10.80 permite la ejecución remota de código. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett Packard Enterprise Operations Orchestration. Authentication is not required to exploit th... • http://www.securityfocus.com/bid/100588 • CWE-20: Improper Input Validation •

CVSS: 10.0EPSS: 60%CPEs: 2EXPL: 0

04 Jan 2017 — A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found. Se ha encontrado una vulnerabilidad de ejecución remota de código en HPE Operations Orchestration en las ediciones Community y Enterprise anteriores a v10.70. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett Packard Enterprise Operations Orchestration. Authentication is not required to exploit this vulnerability. ... • http://www.securityfocus.com/bid/95225 • CWE-502: Deserialization of Untrusted Data •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

19 Nov 2015 — Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Vulnerabilidad de CSRF en HP Operations Orchestration Central 10.x en versiones anteriores a 10.22.001 permite a atacantes remotos secuestrar la autenticación de víctimas no especificadas a través de vectores desconocidos. A potential security vulnerability has been identified in HP Operations Orchestrati... • http://www.securitytracker.com/id/1034177 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 1

15 Dec 2013 — Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en HP Operations Orchestration anterior a la versión 9 permite a atacantes remotos inyectar script web o HTML arbitrario a través de vectores no especificados. Potential security vulnerabilities have been identified with HP Operations Orchestration. The vulnerabilities could be exploited to allow cross-site scripting (X... • https://packetstorm.news/files/id/124542 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 3EXPL: 1

15 Dec 2013 — Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Vulnerabilidad de CSRF en HP Operations Orchestration anterior a la versión 9 permite a atacantes remotos secuestrar la autenticación de víctimas no especificadas a través de vectores desconocidos. Potential security vulnerabilities have been identified with HP Operations Orchestration. The vulnerabilities could be exploited ... • https://packetstorm.news/files/id/124542 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

26 Oct 2010 — Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9.0, when Internet Explorer 6.0 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS)en HP Operations Orchestration anterior v9.0, cuando usa Internet Explorer v6.0, permite a atacantes remotos inyectar código web o HTML de su elección a través de vectores no especificados. • http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02541822 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •