Remote Information Disclosure and SSRF Vulnerability in HPE Service Manager Software
CVE-2016-4371
8HIGH
Key Information:
- Vendor
- HP
- Status
- Vendor
- CVE Published:
- 19 June 2016
Summary
This vulnerability in HPE Service Manager Software allows remote authenticated users to exploit weaknesses associated with the Server, Web Client, Windows Client, and Service Request components. By targeting unspecified vectors, attackers can access sensitive information, modify crucial data, and potentially execute server-side request forgery (SSRF) attacks, increasing the risk of further exploitation and unauthorized access.
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved