First published: Tue Aug 14 2018(Updated: )
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow disclosure of privileged information.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp 3par Service Provider | =sp-4.2.0-ga | |
Hp 3par Service Provider | =sp-4.3.0-ga-17 | |
Hp 3par Service Provider | =sp-4.3.0-ga-24 | |
Hp 3par Service Provider | =sp-4.4.0-ga-22 | |
Hp 3par Service Provider | =sp-4.4.0-ga-30 | |
Hp 3par Service Provider | =sp-4.4.0-ga-53 | |
Hp 3par Service Provider | =sp-4.4.0-ga-58 | |
Hp 3par Service Provider | =sp-4.4.0-ga-86 | |
Hp 3par Service Provider | =sp-4.4.0-ga-88 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7099 is considered a medium severity vulnerability due to its potential for local exploitation to disclose privileged information.
To mitigate CVE-2018-7099, upgrade to 3PAR Service Processor version SP-4.4.0.GA-110(MU7) or later.
CVE-2018-7099 affects HP 3PAR Service Provider versions SP-4.2.0 to SP-4.4.0 prior to SP-4.4.0.GA-110(MU7).
CVE-2018-7099 can lead to the exposure of sensitive privileged information within the system.
There is no documented workaround for CVE-2018-7099, so upgrading to the fixed version is recommended.