Local Information Disclosure in HPE OneView Global Dashboard
CVE-2021-26585
5.5MEDIUM
Summary
A vulnerability has been identified in HPE OneView Global Dashboard, specifically in release 2.31, that may result in local disclosure of privileged information. This issue can potentially expose sensitive information to unauthorized users. Hewlett Packard Enterprise has addressed this security concern in the subsequent release, version 2.32. It is imperative for users to update to the latest version to mitigate the risk associated with this vulnerability.
Affected Version(s)
HPE OneView Global Dashboard only 2.31
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved