First published: Sun Jun 19 2016(Updated: )
HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request components.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 | |
HP Service Manager | =9.34 | |
HP Service Manager | =9.35 | |
HP Service Manager | =9.40 | |
HP Service Manager | =9.41 | |
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 | |
HP Service Manager | =9.34 | |
HP Service Manager | =9.35 | |
HP Service Manager | =9.40 | |
HP Service Manager | =9.41 | |
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 | |
HP Service Manager | =9.34 | |
HP Service Manager | =9.35 | |
HP Service Manager | =9.40 | |
HP Service Manager | =9.41 | |
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 | |
HP Service Manager | =9.34 | |
HP Service Manager | =9.35 | |
HP Service Manager | =9.40 | |
HP Service Manager | =9.41 | |
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 | |
HP Service Manager | =9.34 | |
HP Service Manager | =9.35 | |
HP Service Manager | =9.40 | |
HP Service Manager | =9.41 | |
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 | |
HP Service Manager | =9.34 | |
HP Service Manager | =9.35 | |
HP Service Manager | =9.40 | |
HP Service Manager | =9.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4371 has a medium severity rating which indicates it can lead to sensitive information disclosure and SSRF attacks.
To fix CVE-2016-4371, update to a patched version of HPE Service Manager that addresses the vulnerability.
CVE-2016-4371 affects HPE Service Manager versions 9.30 through 9.41 inclusive.
Yes, CVE-2016-4371 can be exploited by remote authenticated users to conduct various attacks.
The impact of CVE-2016-4371 includes the potential for unauthorized data modification and server-side request forgery.