CVE-2018-7110: Race Condition
A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-7110.
What is the severity of CVE-2018-7110?
The severity of CVE-2018-7110 is medium with a severity value of 5.9.
What is the affected software?
The affected software is HPE Service Governance Framework versions 4.2 and 4.3, as well as Redhat Linux versions 6.0 and 7.0 (in which the vulnerability is not exploitable).
How does the vulnerability in HPE Service Governance Framework manifest?
The vulnerability in HPE Service Governance Framework manifests as a remote unauthorized disclosure of information due to a race condition under high load, where different parameters are transferred to the enabler.
How can I fix the vulnerability in HPE Service Governance Framework?
To fix the vulnerability in HPE Service Governance Framework, it is recommended to apply the necessary patches provided by HPE.