CVE-2016-4394
HP Security Bulletin HPSBMU03691 1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue.
HPE System Management Homepage en versiones anteriores a v7.6 permite a atacantes remotos obtener información sensible a través de vectores no especificados, relacionado con un problema de "HSTS".
Several potential security vulnerabilities have been identified in HPE Insight Control. The vulnerabilities could be exploited remotely resulting in remote denial of Service (DoS), cross-site request forgery (CSRF), remote execution of arbitrary commands, disclosure of sensitive information, cross-site scripting (XSS), bypass access restriction or unauthorized modification. Revision 1 of this advisory.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-04-29 CVE Reserved
- 2016-10-27 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-254: 7PK - Security Features
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/93961 | Vdb Entry | |
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05320149 | 2017-02-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | System Management Homepage Search vendor "Hp" for product "System Management Homepage" | <= 7.5.5.0 Search vendor "Hp" for product "System Management Homepage" and version " <= 7.5.5.0" | - |
Affected
|