ZDI-24-1633: Hewlett Packard Enterprise AutoPass License Server SQL Injection Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Hewlett Packard Enterprise AutoPass License Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-51769.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1633?
The severity of ZDI-24-1633 is rated at 7.5 by the ZDI.
How do I fix ZDI-24-1633?
To fix ZDI-24-1633, it is recommended to apply any available security patches provided by Hewlett Packard Enterprise for the AutoPass License Server.
What type of vulnerability is ZDI-24-1633?
ZDI-24-1633 is a remote information disclosure vulnerability that allows attackers to access sensitive information without authentication.
Who is affected by ZDI-24-1633?
Organizations using Hewlett Packard Enterprise AutoPass License Server are affected by ZDI-24-1633.
Is authentication required to exploit ZDI-24-1633?
No, authentication is not required to exploit the ZDI-24-1633 vulnerability.