Vulnerability index

Browse CVEs

1,743 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

System Management Homepage HIGH 7.5
CVE-2016-4395

HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" …

Fix: after 7.5.5.0
Fix from $1,950 2016-10-28
System Management Homepage MEDIUM 6.5
CVE-2016-4394

HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issu…

Fix: after 7.5.5.0
Fix from $1,600 2016-10-28
System Management Homepage MEDIUM 5.4
CVE-2016-4393

HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related t…

Fix: after 7.5.5.0
Fix from $1,600 2016-10-28
Keyview HIGH 8.1
CVE-2016-4390EPSS 5%

The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerabilit…

No fix yet
Fix from $1,950 2016-10-05
Keyview HIGH 8.1
CVE-2016-4389EPSS 5%

The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerabilit…

Mitigation only
Fix from $1,950 2016-10-05
Keyview HIGH 8.1
CVE-2016-4388EPSS 5%

The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerabilit…

Mitigation only
Fix from $1,950 2016-10-05
Keyview HIGH 8.1
CVE-2016-4387EPSS 9%

The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerabilit…

Mitigation only
Fix from $1,950 2016-10-05
Network Automation HIGH 7.8
CVE-2016-4386

HPE Network Automation Software 10.10 allows local users to write to arbitrary files via unspecified vectors.

Mitigation only
Fix from $1,950 2016-09-29
Network Automation HIGH 7.3
CVE-2016-4385

The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execu…

Mitigation only
Fix from $1,950 2016-09-29
Loadrunner HIGH 8.6
CVE-2016-4384

HPE Performance Center before 12.50 and LoadRunner before 12.50 allow remote attackers to cause a denial of service via unspecified vectors.

Fix: after 12.20
Fix from $1,950 2016-09-21
Performance Center HIGH 8.3
CVE-2016-4382

HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass intended access restrictions via unspecified vectors, …

Mitigation only
Fix from $1,950 2016-09-21
Operations Manager MEDIUM 5.4
CVE-2016-4380

Cross-site scripting (XSS) vulnerability in the AdminUI in HPE Operations Manager 9.21.x before 9.21.130 allows remote authenticated users to inject …

Fix: after 9.21
Fix from $1,600 2016-09-08
Integrated Lights Out 3 Firmware CRITICAL 9.8
CVE-2016-4375

Multiple unspecified vulnerabilities in HPE Integrated Lights-Out 3 (aka iLO 3) firmware before 1.88, Integrated Lights-Out 4 (aka iLO 4) firmware be…

Mitigation only
Fix from $2,300 2016-09-08
Xp 9000 Command View HIGH 7.5
CVE-2016-4378

The (1) Device Manager, (2) Tiered Storage Manager, (3) Replication Manager, (4) Replication Monitor, and (5) Hitachi Automation Director (HAD) compo…

Fix: after 8.4.0
Fix from $1,950 2016-08-26
Converged Infrastructure Solution Sizer Suite HIGH 8.1
CVE-2016-4377EPSS 7%

HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2,…

Fix: after 16.12.0
Fix from $1,950 2016-08-22
Release Control HIGH 7.7
CVE-2016-4374

HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) att…

Patch available
Fix from $1,950 2016-08-08
Operations Manager CRITICAL 9.8
CVE-2016-4373

The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a cr…

Fix: after 9.21.120
Fix from $2,300 2016-08-01
Intelligent Management Center Application Performance Manager CRITICAL 9.8
CVE-2016-4372EPSS 19%

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02…

Fix: after 7.2
Fix from $2,300 2016-07-15
Service Manager HIGH 8.0
CVE-2016-4371

HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, mo…

Mitigation only
Fix from $1,950 2016-06-19
Discovery And Dependency Mapping Inventory HIGH 8.8
CVE-2016-4369

HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated u…

Mitigation only
Fix from $1,950 2016-06-08
Universal Cmbd Foundation CRITICAL 9.8
CVE-2016-4368

HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remo…

Mitigation only
Fix from $2,300 2016-06-08
Universal Cmbd Foundation HIGH 7.5
CVE-2016-4367EPSS 8%

The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive infor…

Mitigation only
Fix from $1,950 2016-06-08
Systems Insight Manager CRITICAL 9.8
CVE-2016-4366

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via…

Fix: after 7.5
Fix from $2,300 2016-06-08
Insight Control Server Deployment HIGH 7.5
CVE-2016-4365

HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.

No fix yet
Fix from $1,950 2016-06-08
Insight Control Server Deployment HIGH 8.4
CVE-2016-4364

HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors.

No fix yet
Fix from $1,950 2016-06-08
Insight Control Server Deployment MEDIUM 6.1
CVE-2016-4363

HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors.

No fix yet
Fix from $1,600 2016-06-08
Insight Control Server Deployment HIGH 8.1
CVE-2016-4362

HPE Insight Control server deployment allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

Mitigation only
Fix from $1,950 2016-06-08
Performance Center HIGH 7.5
CVE-2016-4361EPSS 8%

HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance …

Mitigation only
Fix from $1,950 2016-06-08
Loadrunner CRITICAL 9.1
CVE-2016-4360EPSS 9%

web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.0…

Mitigation only
Fix from $2,300 2016-06-08
Loadrunner CRITICAL 9.8
CVE-2016-4359EPSS 16%

Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 th…

Mitigation only
Fix from $2,300 2016-06-08