Vulnerability index

Browse CVEs

1,743 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

P9000 Command View Advanced Edition Software CRITICAL 9.8
CVE-2016-2003

HPE P9000 Command View Advanced Edition Software (CVAE) 7.x and 8.x before 8.4.0-00 and XP7 CVAE 7.x and 8.x before 8.4.0-00 allow remote attackers t…

Patch available
Fix from $2,300 2016-04-20
Universal Cmbd Foundation HIGH 7.4
CVE-2016-2001

HPE Universal CMDB Foundation 10.0, 10.01, 10.10, 10.11, and 10.20 allows remote attackers to obtain sensitive information or conduct URL redirection…

Patch available
Fix from $1,950 2016-04-12
Asset Manager CRITICAL 9.8
CVE-2016-2000

HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a craft…

Patch available
Fix from $2,300 2016-04-05
Service Manager CRITICAL 9.8
CVE-2016-1998EPSS 7%

HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized J…

Patch available
Fix from $2,300 2016-03-22
Operations Orchestration CRITICAL 9.8
CVE-2016-1997EPSS 7%

HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands…

Fix: after 1.5.3
Fix from $2,300 2016-03-22
Support Assistant CRITICAL 9.8
CVE-2016-2245EPSS 6%

HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.

Fix: after 8.1.40.3
Fix from $2,300 2016-03-19
System Management Homepage HIGH 7.7
CVE-2016-1996

HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors.

Fix: after 7.5.3.1
Fix from $1,950 2016-03-18
System Management Homepage CRITICAL 9.8
CVE-2016-1995EPSS 10%

HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 7.5.3.1
Fix from $2,300 2016-03-18
System Management Homepage MEDIUM 6.5
CVE-2016-1994

HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.

Fix: after 7.5.3.1
Fix from $1,600 2016-03-18
System Management Homepage HIGH 8.1
CVE-2016-1993

HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

Fix: after 7.5.3.1
Fix from $1,950 2016-03-18
Enterprise Security Manager MEDIUM 6.5
CVE-2016-1992

HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecifie…

Fix: after 6.9.0
Fix from $1,600 2016-03-17
Network Automation CRITICAL 9.8
CVE-2016-1989EPSS 11%

HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive informatio…

Patch available
Fix from $2,300 2016-03-15
Network Automation CRITICAL 9.8
CVE-2016-1988EPSS 11%

HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive informatio…

Patch available
Fix from $2,300 2016-03-15
Futuresmart Firmware MEDIUM 5.9
CVE-2016-2244

HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information vi…

Fix: after 3.7
Fix from $1,600 2016-03-04
700 Series Firmware HIGH 7.9
CVE-2016-2243

Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.

Mitigation only
Fix from $1,950 2016-03-04
Hp Ux Ipfilter MEDIUM 5.9
CVE-2016-1987

HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via uns…

Mitigation only
Fix from $1,600 2016-02-18
Continuous Delivery Automation CRITICAL 9.8
CVE-2016-1986

HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t…

Patch available
Fix from $2,300 2016-02-12
Operations Manager CRITICAL 10.0
CVE-2016-1985EPSS 7%

HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to …

Patch available
Fix from $2,300 2016-01-30
Arcsight Logger MEDIUM 6.3
CVE-2015-6864

HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) clien…

Fix: after 6.1
Fix from $1,600 2016-01-16
Arcsight Logger HIGH 7.3
CVE-2015-6863

HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certific…

Fix: after 6.1
Fix from $1,950 2016-01-16
Ucmdb Browser HIGH 8.4
CVE-2015-6862

HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.

Patch available
Fix from $1,950 2016-01-08
Network Switch Software HIGH 8.4
CVE-2015-6860

HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different …

Fix: after 15.18.0
Fix from $1,950 2016-01-05
Network Switch Software HIGH 7.8
CVE-2015-6859

HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different …

Fix: after 15.18.0
Fix from $1,950 2016-01-05
Storeonce Backup System Software MEDIUM 5.4
CVE-2015-5447

Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to inject arbitrary w…

Fix: after 3.13.0
Fix from $1,600 2016-01-05
Storeonce Backup System Software HIGH 7.5
CVE-2015-5446

HP StoreOnce Backup system software before 3.13.1 allows remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 3.13.0
Fix from $1,950 2016-01-05
Storeonce Backup System Software HIGH 8.8
CVE-2015-5445

Cross-site request forgery (CSRF) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to hijack the …

Fix: after 3.13.0
Fix from $1,950 2016-01-05
Jg786a Hp Flexfabric 12500 4 Port 100gbe Cfp Fd MEDIUM 6.5
CVE-2015-5434

HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cau…

Patch available
Fix from $1,600 2016-01-05
Loadrunner HIGH 7.2
CVE-2015-6857

Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2015-11-26
Operations Orchestration MEDIUM 6.8
CVE-2015-5451

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the au…

Fix: after 10.22.0
Fix from $1,600 2015-11-23
Arcsight Connector Appliance HIGH 7.2
CVE-2015-6030

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute …

Fix: after 7.1.3
Fix from $1,950 2015-11-04