CVE-2014-2633: CSRF
Published Aug 23, 2014
·Updated
Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Affected Software
6 affected components
hp Service Manager=7.21
hp Service Manager=9.21
hp Service Manager=9.30
hp Service Manager=9.31
hp Service Manager=9.32
hp Service Manager=9.33
Event History
Aug 23, 2014
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2633?
CVE-2014-2633 is classified as a moderate severity cross-site request forgery vulnerability.
2
How do I fix CVE-2014-2633?
To mitigate CVE-2014-2633, upgrade to HP Service Manager version 9.34 or apply relevant security patches provided by HP.
3
What versions of HP Service Manager are affected by CVE-2014-2633?
CVE-2014-2633 affects HP Service Manager versions 7.21 and 9.21 through 9.33.
4
What type of vulnerability is CVE-2014-2633?
CVE-2014-2633 is a cross-site request forgery (CSRF) vulnerability.
5
Who are the potential attackers for CVE-2014-2633?
Remote attackers can exploit CVE-2014-2633 to hijack authentication of users in affected versions.