First published: Wed Jun 05 2019(Updated: )
A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Intelligent Management Center | <7.3 | |
HP Intelligent Management Center | =7.3 | |
HP Intelligent Management Center | =7.3-e0503 | |
HP Intelligent Management Center | =7.3-e0504 | |
HP Intelligent Management Center | =7.3-e0504p02 | |
HP Intelligent Management Center | =7.3-e0504p04 | |
HP Intelligent Management Center | =7.3-e0506 | |
HP Intelligent Management Center | =7.3-e0506p03 | |
HP Intelligent Management Center | =7.3-e0506p07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11975 is classified as a critical SQL injection vulnerability that allows code execution.
To fix CVE-2019-11975, upgrade to HPE Intelligent Management Center version 7.3 or later.
Affected versions include all versions of HP Intelligent Management Center prior to 7.3 E0506P09.
Attackers can potentially execute arbitrary SQL code on the server, leading to data compromise.
Yes, CVE-2019-11975 can be exploited remotely by an attacker with access to the vulnerable software.