First published: Fri Nov 06 2020(Updated: )
There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OneView | =5.0 | |
HP OneView | =5.00.01 | |
HP OneView | =5.00.02 | |
HP OneView | =5.2 | |
HP OneView | =5.3 | |
HP OneView | =5.4 | |
HP OneView | =5.20.01 | |
Hp Synergy Composer | =5.0 | |
Hp Synergy Composer | =5.00.01 | |
Hp Synergy Composer | =5.00.02 | |
Hp Synergy Composer | =5.2 | |
Hp Synergy Composer | =5.3 | |
Hp Synergy Composer | =5.4 | |
Hp Synergy Composer | =5.20.01 | |
Hp Synergy Composer 2 | =5.0 | |
Hp Synergy Composer 2 | =5.00.01 | |
Hp Synergy Composer 2 | =5.00.02 | |
Hp Synergy Composer 2 | =5.2 | |
Hp Synergy Composer 2 | =5.3 | |
Hp Synergy Composer 2 | =5.4 | |
Hp Synergy Composer 2 | =5.20.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2020-7198.
The severity of CVE-2020-7198 is high with a CVSS score of 8.8.
The affected software for CVE-2020-7198 includes HP OneView and Hp Synergy Composer versions 5.0, 5.00.01, 5.00.02, 5.2, 5.3, 5.4, and 5.20.01, as well as Hp Synergy Composer 2 versions 5.0, 5.00.01, 5.00.02, 5.2, 5.3, 5.4, and 5.20.01.
To fix CVE-2020-7198, you need to update to version 5.5 of OneView, Composer, or Composer2.
You can find more information about CVE-2020-7198 [here](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04047en_us).