First published: Tue Aug 14 2018(Updated: )
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow directory traversal.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp 3par Service Provider | =sp-4.2.0-ga | |
Hp 3par Service Provider | =sp-4.3.0-ga-17 | |
Hp 3par Service Provider | =sp-4.3.0-ga-24 | |
Hp 3par Service Provider | =sp-4.4.0-ga-22 | |
Hp 3par Service Provider | =sp-4.4.0-ga-30 | |
Hp 3par Service Provider | =sp-4.4.0-ga-53 | |
Hp 3par Service Provider | =sp-4.4.0-ga-58 | |
Hp 3par Service Provider | =sp-4.4.0-ga-86 | |
Hp 3par Service Provider | =sp-4.4.0-ga-88 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7098 is classified as a security vulnerability that may allow directory traversal and could be locally exploited.
To fix CVE-2018-7098, upgrade your 3PAR Service Processor to version SP-4.4.0.GA-110(MU7) or later.
CVE-2018-7098 affects various versions of the HP 3PAR Service Provider including SP-4.2.0, SP-4.3.0, and SP-4.4.0 prior to GA-110.
No, CVE-2018-7098 requires local access to exploit the vulnerability.
The potential impact of CVE-2018-7098 includes unauthorized access to files and directories on the affected system.