CVE-2019-11999
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Potential security vulnerabilities have been identified in HPE OpenCall Media Platform (OCMP) resulting in remote arbitrary file download and cross site scripting. HPE has made the following updates available to resolve the vulnerability in the impacted versions of OCMP. * For OCMP version 4.4.X - please upgrade to OCMP 4.4.8 and then install RP806 * For OCMP 4.5.x please contact HPE Technical Support to obtain the necessary software updates.
Se han identificado potenciales vulnerabilidades de seguridad en HPE OpenCall Media Platform (OCMP), resultando en una descarga de archivos arbitraria remota y una vulnerabilidad de tipo cross site scripting. HPE ha puesto a disposición las siguientes actualizaciones para resolver la vulnerabilidad en las versiones afectadas de OCMP. * Para OCMP versión 4.4.X - por favor, actualice al OCMP versión 4.4.8 y luego instale RP806 * Para OCMP versión 4.5.x por favor, contacte a Soporte Técnico de HPE para obtener las actualizaciones de software necesarias.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-13 CVE Reserved
- 2020-04-16 CVE Published
- 2024-05-26 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hpe Search vendor "Hpe" | Opencall Media Platform Search vendor "Hpe" for product "Opencall Media Platform" | >= 4.4.0 < 4.4.8 Search vendor "Hpe" for product "Opencall Media Platform" and version " >= 4.4.0 < 4.4.8" | - |
Affected
| ||||||
Hpe Search vendor "Hpe" | Opencall Media Platform Search vendor "Hpe" for product "Opencall Media Platform" | >= 4.5.0 < 4.5.2 Search vendor "Hpe" for product "Opencall Media Platform" and version " >= 4.5.0 < 4.5.2" | - |
Affected
|