First published: Thu Apr 16 2020(Updated: )
Potential security vulnerabilities have been identified in HPE OpenCall Media Platform (OCMP) resulting in remote arbitrary file download and cross site scripting. HPE has made the following updates available to resolve the vulnerability in the impacted versions of OCMP. * For OCMP version 4.4.X - please upgrade to OCMP 4.4.8 and then install RP806 * For OCMP 4.5.x please contact HPE Technical Support to obtain the necessary software updates.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenCall Media Platform | >=4.4.0<4.4.8 | |
HP OpenCall Media Platform | >=4.5.0<4.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11999 has been classified as a high-severity vulnerability due to its potential for remote arbitrary file download and cross site scripting.
To fix CVE-2019-11999, upgrade HPE OpenCall Media Platform to version 4.4.9 or later, or to version 4.5.3 or later.
CVE-2019-11999 affects HPE OpenCall Media Platform versions 4.4.0 through 4.4.8 and 4.5.0 through 4.5.2.
CVE-2019-11999 is associated with vulnerabilities that allow remote arbitrary file downloads and cross site scripting exploits.
No specific workaround is suggested for CVE-2019-11999, so applying the recommended updates is advised to mitigate the risks.