Remote Information Disclosure and URL Redirection in HPE Universal CMDB
CVE-2016-2001
7.4HIGH
Summary
The HPE Universal CMDB Foundation versions 10.0 through 10.20 are susceptible to vulnerabilities that allow remote attackers to access sensitive information and perform unauthorized URL redirection. Attack vectors are unspecified, indicating potential weaknesses that could be exploited in various manners, leading to a breach of data confidentiality and integrity. Organizations using these versions should take immediate action to secure their systems and patch the vulnerability.
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved