First published: Sat Aug 23 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Service Manager | =7.21 | |
HP Service Manager | =9.21 | |
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2633 is classified as a moderate severity cross-site request forgery vulnerability.
To mitigate CVE-2014-2633, upgrade to HP Service Manager version 9.34 or apply relevant security patches provided by HP.
CVE-2014-2633 affects HP Service Manager versions 7.21 and 9.21 through 9.33.
CVE-2014-2633 is a cross-site request forgery (CSRF) vulnerability.
Remote attackers can exploit CVE-2014-2633 to hijack authentication of users in affected versions.