QID 731099
Date Published: 2024-01-31
QID 731099: Hewlett Packard Enterprise (HPE) OneView Multiple Vulnerabilities (HPESBGN04586)
HPE OneView is an IT infrastructure management software that streamlines IT operations and controls all of your systems via a single global dashboard.
Potential security vulnerabilities have been identified in Hewlett Packard Enterprise OneView Software. These vulnerabilities could be exploited to allow remote code execution, local privilege escalation, Server-Side Request Forgery, Denial-of-Service and unauthenticated Restore.
Affected Version
HPE OneView - All versions prior to 8.70
QID detection logic (Un-Auth)
This qid send GET request to /rest/appliance/nodeinfo/version to check software version
These vulnerabilities could be exploited to allow remote code execution, local privilege escalation, Server-Side Request Forgery, Denial-of-Service and unauthenticated Restore.
CVEs related to QID 731099
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| HPESBGN04586 |
|