8

CVE-2016-4371

HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request components.

Data is provided by the National Vulnerability Database (NVD)
HpService Manager Version9.30
HpService Manager Version9.31
HpService Manager Version9.32
HpService Manager Version9.33
HpService Manager Version9.34
HpService Manager Version9.35
HpService Manager Version9.40
HpService Manager Version9.41
HpService Manager Mobility Version9.30
HpService Manager Mobility Version9.31
HpService Manager Mobility Version9.32
HpService Manager Mobility Version9.33
HpService Manager Mobility Version9.34
HpService Manager Mobility Version9.35
HpService Manager Mobility Version9.40
HpService Manager Mobility Version9.41
HpService Manager Server Version9.30
HpService Manager Server Version9.31
HpService Manager Server Version9.32
HpService Manager Server Version9.33
HpService Manager Server Version9.34
HpService Manager Server Version9.35
HpService Manager Server Version9.40
HpService Manager Server Version9.41
HpService Manager Web Client Version9.30
HpService Manager Web Client Version9.31
HpService Manager Web Client Version9.32
HpService Manager Web Client Version9.33
HpService Manager Web Client Version9.34
HpService Manager Web Client Version9.35
HpService Manager Web Client Version9.40
HpService Manager Web Client Version9.41
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.178
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8 2.1 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.