Local Information Disclosure in HPE OneView Global Dashboard
CVE-2021-26585

5.5MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
24 June 2021

Summary

A vulnerability has been identified in HPE OneView Global Dashboard, specifically in release 2.31, that may result in local disclosure of privileged information. This issue can potentially expose sensitive information to unauthorized users. Hewlett Packard Enterprise has addressed this security concern in the subsequent release, version 2.32. It is imperative for users to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

HPE OneView Global Dashboard only 2.31

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.