Remote Information Disclosure and SSRF Vulnerability in HPE Service Manager Software
CVE-2016-4371

8HIGH

Summary

This vulnerability in HPE Service Manager Software allows remote authenticated users to exploit weaknesses associated with the Server, Web Client, Windows Client, and Service Request components. By targeting unspecified vectors, attackers can access sensitive information, modify crucial data, and potentially execute server-side request forgery (SSRF) attacks, increasing the risk of further exploitation and unauthorized access.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.