Open Redirect Vulnerability in HPE OneView Global Dashboard
CVE-2022-37927

6.1MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
12 December 2022

Summary

The Open Redirect vulnerability in HPE OneView Global Dashboard allows an attacker to redirect users to untrusted external sites. This security flaw can be exploited to facilitate phishing attacks or distribute malware, as it undermines the user’s ability to identify legitimate links. Victims may unintentionally disclose sensitive information, falling prey to malicious actors. Organizations are advised to apply the necessary security updates and implement robust input validation measures to mitigate potential risks.

Affected Version(s)

HPE OneView Global Dashboard (OVGD) Prior to 2.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.