CVE-2018-7107
Summary
| CVE | CVE-2018-7107 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-27 18:29:00 UTC |
| Updated | 2018-11-21 23:11:00 UTC |
| Description | A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hpe | Device Entitlement Gateway | 3.2.4 | All | All | All |
| Application | Hpe | Device Entitlement Gateway | 3.3 | All | All | All |
| Application | Hpe | Device Entitlement Gateway | 3.3.1 | All | All | All |
| Application | Hpe | Device Entitlement Gateway | 3.2.4 | All | All | All |
| Application | Hpe | Device Entitlement Gateway | 3.3 | All | All | All |
| Application | Hpe | Device Entitlement Gateway | 3.3.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Document Display | HPE Support Center | CONFIRM | support.hpe.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.