← Back

Hp

hp

2,335 CVEs • 17,248 products

Products (17,248)

Click to collapse
Toggle
Hp Ux
hp-ux
Instantos
instantos
Tru64
tru64
Loadrunner
loadrunner
Sitescope
sitescope
Openvms
openvms
Oneview
oneview

CVEs (2,335)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Ilo Amplifier Pack
Nov 21, 2024
Dec 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.
1Hp
2Storeever 1/8 G2 Tape Autoloader Firmware
Storeever Msl2024 Firmware
Nov 21, 2024
Dec 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forger...Show more
A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).Show less
1Hp
1Systems Insight Manager
Nov 21, 2024
Dec 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.
1Hp
1Edgeline Infrastructure Manager
Nov 21, 2024
Dec 2, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authe...Show more
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration.Show less
1Hp
3Oneview
Synergy ComposerSynergy Composer 2
Nov 21, 2024
Nov 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneVi...Show more
There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.Show less
1Hp
21Apollo 2000 Firmware
Apollo 4200 Gen10 FirmwareApollo 4500 Firmware+18 more
Nov 21, 2024
Nov 5, 2020
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To...Show more
A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this issue in the impacted Gen 10 servers listed. HPE recommends using appropriate physical security methods as a compensating control to disallow an attacker from having physical access to the server main circuit board.Show less
1Hp
1Storeserv Management Console
Nov 21, 2024
Oct 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has p...Show more
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console (SSMC) software 3.7.0.0* Upgrade to HPE 3PAR StoreServ Management Console 3.7.1.1 or later.Show less
1Hp
2Bluedata Epic
Ezmeral Container Platform
Nov 21, 2024
Oct 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval...Show more
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".Show less
2Hp
Microfocus
7Application Performance Management
Data Center AutomationHybrid Cloud Management+4 more
Nov 21, 2024
Oct 22, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2....Show more
Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.Show less
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A iccselectrules expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A perfaddormoddevicemonitor expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A devicethresholdconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A devsoftsel expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A deviceselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A faultflasheventselectfact expression language injectionremote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A userselectpagingcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A reportpage index expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A powershellconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A tvxlanlegend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).