QID 375442

Date Published: 2021-04-14

QID 375442: HPE System Management Homepage Multiple Vulnerabilities (HPESBMU03593)

The HP System Management Homepage (SMH) is a web-based interface that consolidates the management of ProLiant and Integrity servers running Microsoft Windows or Linux, or HP 9000 and HP Integrity servers running HP-UX 11i.

Multiple potential security vulnerabilities have been identified in HPE System Management Homepage (SMH) on Windows and Linux.

Affected Versions:
HPE System Management Homepage versions prior to 7.5.5

The vulnerabilities could be exploited remotely resulting in Denial of Service (DoS), remote code execution, or disclosure of sensitive information.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to HP SMH v7.5.5 or later to remediate these vulnerabilities.
    Software Advisories
    Advisory ID Software Component Link
    HPESBMU03593 URL Logo support.hpe.com/hpesc/public/docDisplay?docId=emr_na-c05111017