CVE-2015-2140
published 2015-08-27CVE-2015-2140: HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to…
PriorityP429medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.87%
76.9th percentile
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | systems_insight_manager | <= 7.4 | — |
| openstack | nova | >= 12.0.0 < 12.0.3 | 12.0.3 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h57m-jqm8-q82f: HP Systems Insight Manager (SIM) before 7
ghsa_unreviewed·2022-05-17
CVE-2015-2140 [MEDIUM] CWE-20 GHSA-h57m-jqm8-q82f: HP Systems Insight Manager (SIM) before 7
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
GHSA
OpenStack Nova host data access through resize/migration
ghsa·2022-05-14
CVE-2016-2140 [MEDIUM] CWE-200 OpenStack Nova host data access through resize/migration
OpenStack Nova host data access through resize/migration
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
Red Hat
openstack-nova: Host data leak through resize/migration
vendor_redhat·2016-03-08·CVSS 5.3
CVE-2016-2140 [MEDIUM] CWE-200 openstack-nova: Host data leak through resize/migration
openstack-nova: Host data leak through resize/migration
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
An information-exposure flaw was found in the OpenStack Compute (nova) resize and migrate functionality. An authenticated user could write a malicious qcow header to an ephemeral or root disk, referencing a block device as a backing file. With a subsequent resize or migration, file system content on the specified device would be leaked to the user. Only setups using libvirt with raw storage and "use_cow_images = False" were affected.
Package: openstack-nova
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04762744https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04774019https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04762744https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04774019
2015-08-27
Published