SQL Injection Vulnerability in HPE Intelligent Management Center Products
CVE-2019-11977

8.8HIGH

Key Information:

Vendor

HP

Vendor
CVE Published:
5 June 2019

What is CVE-2019-11977?

A SQL injection vulnerability was discovered in HPE Intelligent Management Center (IMC) PLAT prior to version 7.3 E0506P09. This flaw allows an attacker to execute arbitrary code on the affected system by sending specially crafted SQL queries. The impact of this vulnerability can lead to unauthorized access and manipulation of the database, potentially compromising sensitive information and system integrity. Users are urged to upgrade to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

HPE Intelligent Management Center (IMC) PLAT 7.3 E0506P09 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-11977 : SQL Injection Vulnerability in HPE Intelligent Management Center Products