CVE-2016-4371
https://notcve.org/view.php?id=CVE-2016-4371
HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request components. HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40 y 9.41 permite a usuarios remotos autenticados obtener información sensible, modificar datos y llevar a cabo ataques de SSRF a través de vectores no especificados, relacionado con los componentes Server, Web Client, Windows Client y Service Request. • https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05167176 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-6198
https://notcve.org/view.php?id=CVE-2013-6198
Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Cross-site scripting (XSS) en HP Service Manager WebTier y Windows Client 9.20 y 9.21 anterior a 9.21.661 p8 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c04052075 http://www.securitytracker.com/id/1029541 https://exchange.xforce.ibmcloud.com/vulnerabilities/89975 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-6197
https://notcve.org/view.php?id=CVE-2013-6197
Unspecified vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote authenticated users to execute arbitrary code via unknown vectors. Vulnerabilidad no especificada en HP Service Manager WebTier y Windows Client 9.20 y 9.21 antes de 9.21.661 p8 permite a los usuarios remotos autenticados ejecutar código arbitrario a través de vectores desconocidos. • http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c04052075 http://www.securitytracker.com/id/1029541 https://exchange.xforce.ibmcloud.com/vulnerabilities/89974 •