First published: Wed Oct 17 2018(Updated: )
A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Service Governance Framework | =4.2 | |
HPE Service Governance Framework | =4.3 | |
Redhat Linux | =6.0 | |
Redhat Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-7110.
The severity of CVE-2018-7110 is medium with a severity value of 5.9.
The affected software is HPE Service Governance Framework versions 4.2 and 4.3, as well as Redhat Linux versions 6.0 and 7.0 (in which the vulnerability is not exploitable).
The vulnerability in HPE Service Governance Framework manifests as a remote unauthorized disclosure of information due to a race condition under high load, where different parameters are transferred to the enabler.
To fix the vulnerability in HPE Service Governance Framework, it is recommended to apply the necessary patches provided by HPE.