CVE-2014-7874: CSRF
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7874?
CVE-2014-7874 is classified as a moderate severity vulnerability due to its potential for cross-site request forgery.
How do I fix CVE-2014-7874?
To fix CVE-2014-7874, upgrade to HP System Management Homepage version 3.2.3 or later for HP-UX B.11.23 or version 3.2.8 or later for HP-UX B.11.31.
What type of vulnerability is CVE-2014-7874?
CVE-2014-7874 is a cross-site request forgery (CSRF) vulnerability.
Which systems are affected by CVE-2014-7874?
CVE-2014-7874 affects HP System Management Homepage versions before 3.2.3 on HP-UX B.11.23 and before 3.2.8 on HP-UX B.11.31.
Can CVE-2014-7874 be exploited remotely?
Yes, CVE-2014-7874 can be exploited remotely to hijack the authentication of unspecified victims.