First published: Tue Apr 25 2023(Updated: )
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OneView | <6.60.04 | |
HP OneView | >=7.0<8.2 | |
HPE OneView Global Dashboard | <2.72 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-28084.
The title of this vulnerability is 'HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens'.
HPE OneView versions up to and including 6.60.04, HPE OneView versions 7.0 to 8.2, and HPE OneView Global Dashboard versions up to and including 2.72 are affected by this vulnerability.
The severity of CVE-2023-28084 is medium with a CVSS score of 5.5.
To fix this vulnerability, you should update HPE OneView and HPE OneView Global Dashboard to the latest versions available.