First published: Fri Apr 14 2023(Updated: )
HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OneView | >=7.0<=8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28091 is a vulnerability in the HPE OneView virtual appliance that allows the 'Migrate server hardware' option to expose sensitive information in an HPE OneView support dump.
The severity of CVE-2023-28091 is medium with a CVSS score of 5.5.
CVE-2023-28091 affects HPE OneView virtual appliance versions 7.0 to 8.1.
To fix CVE-2023-28091, it is recommended to update HPE OneView to a version that is not affected by this vulnerability as soon as it becomes available.
More information about CVE-2023-28091 can be found at the following link: [link](https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04467en_us)