Cross-Site Request Forgery Vulnerability in HPE 3PAR Service Processor
CVE-2018-7097

8.8HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
14 August 2018

Summary

A security vulnerability in the HPE 3PAR Service Processor can be remotely exploited, allowing attackers to perform unauthorized actions by tricking users into sending requests without their knowledge. The flaw exists in versions prior to SP-4.4.0.GA-110(MU7), emphasizing the need for timely updates to mitigate potential risks. Users of affected versions should implement necessary patches to secure their systems against this vulnerability.

Affected Version(s)

HPE 3PAR Service Processors Prior to SP-4.4.0.GA-110(MU7)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.