2.1

CVE-2008-3539

Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 and earlier, HPSI OID Connector 1.02 and earlier, HPSI IBM Tivoli Dir Connector 1.02 and earlier, HPSI TOPSecret Connector 2.22.001 and earlier, HPSI RACF Connector 1.12.001 and earlier, HPSI ACF2 Connector 1.02 and earlier, HPSI OpenLDAP Connector 1.02 and earlier, and HPSI BiDir DirX Connector 1.00.003 and earlier, allows local users to obtain sensitive information via unknown vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpHpsi Acf2 Connector Version <= 1.02
   MicrosoftWindows
HpHpsi Active Directory Connector Version <= 1.70.003
   MicrosoftWindows
HpHpsi Active Directory Connector Version <= 2.10.002
   MicrosoftWindows
HpHpsi Active Directory Connector Version <= 2.20
   MicrosoftWindows
HpHpsi Active Directory Connector Version <= 2.30
   MicrosoftWindows
HpHpsi Bidir Dirx Connector Version <= 1.00.003
   MicrosoftWindows
HpHpsi Edirectory Connector Version <= 1.12
   MicrosoftWindows
HpHpsi Etrust Connector Version <= 1.02
   MicrosoftWindows
HpHpsi Oid Connector Version <= 1.02
   MicrosoftWindows
HpHpsi Openldap Connector Version <= 1.02
   MicrosoftWindows
HpHpsi Racf Connector Version <= 1.12.001
   MicrosoftWindows
HpHpsi Sunone Connector Version <= 1.14
   MicrosoftWindows
HpHpsi Topsecret Connector Version <= 2.22.001
   MicrosoftWindows
HpIbm Tivoli Dir Connector Version <= 1.02
   MicrosoftWindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.275
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.