First published: Thu Jun 09 2016(Updated: )
HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to execute arbitrary commands or obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Project and Portfolio Management Center | =9.20 | |
HP Project and Portfolio Management Center | =9.21 | |
HP Project and Portfolio Management Center | =9.22 | |
HP Project and Portfolio Management Center | =9.30 | |
HP Project and Portfolio Management Center | =9.31 | |
HP Project and Portfolio Management Center | =9.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4370 has a high severity rating due to its potential to allow remote authenticated users to execute arbitrary commands.
To fix CVE-2016-4370, upgrade HPE Project and Portfolio Management Center to version 9.32.0002 or later.
CVE-2016-4370 affects HPE Project and Portfolio Management Center versions 9.20, 9.21, 9.22, 9.30, 9.31, and prior to 9.32.0002.
CVE-2016-4370 can potentially lead to unauthorized access to sensitive information stored within HPE Project and Portfolio Management Center.
Organizations using affected versions of HPE Project and Portfolio Management Center are at risk due to CVE-2016-4370.