{"api_version":"1","generated_at":"2026-07-23T09:11:58+00:00","cve":"CVE-2017-5798","urls":{"html":"https://cve.report/CVE-2017-5798","api":"https://cve.report/api/cve/CVE-2017-5798.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5798","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5798"},"summary":{"title":"CVE-2017-5798","description":"A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).","state":"PUBLIC","assigner":"security-alert@hpe.com","published_at":"2018-02-15 22:29:00","updated_at":"2018-03-15 16:27:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/98013","name":"98013","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"HP OpenCall Media Platform Multiple Cross Site Scripting and Remote File Include Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03686en_us","name":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03686en_us","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Document Display | HPE Support Center","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/41927/","name":"41927","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion - Multiple webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5798","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5798","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5798","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"opencall_media_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5798","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"opencall_media_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-alert@hpe.com","DATE_PUBLIC":"2017-03-20T00:00:00","ID":"CVE-2017-5798","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"OpenCall Media Platform (OCMP)","version":{"version_data":[{"version_value":"prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x)"}]}}]},"vendor_name":"Hewlett Packard Enterprise"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Remote Code Execution"}]}]},"references":{"reference_data":[{"name":"41927","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/41927/"},{"name":"98013","refsource":"BID","url":"http://www.securityfocus.com/bid/98013"},{"name":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03686en_us","refsource":"CONFIRM","url":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03686en_us"}]}},"nvd":{"publishedDate":"2018-02-15 22:29:00","lastModifiedDate":"2018-03-15 16:27:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hp:opencall_media_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.4.7","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hp:opencall_media_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.4.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5798","Ordinal":"102380","Title":"CVE-2017-5798","CVE":"CVE-2017-5798","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5798","Ordinal":"1","NoteData":"A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5798","Ordinal":"2","NoteData":"2018-02-15","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5798","Ordinal":"3","NoteData":"2018-02-16","Type":"Other","Title":"Modified"}]}}}