This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.
HPE OneView may have a missing passphrase during restore.
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
An HPE OneView appliance dump may expose SNMPv3 read credentials
An HPE OneView appliance dump may expose proxy credential settings
An HPE OneView appliance dump may expose OneView user accounts
HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump
A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality, integrity, and availability. To exploit this vulnerability, HPE OneView must be configured with credential access to external repositories. HPE has provided a software update to resolve this vulnerability in HPE OneView.
A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.