CVE-2016-1996
published 2016-03-18CVE-2016-1996: HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors.
PriorityP433high7.7CVSS 3.0
AVLACLPRNUINSUCHIHAN
EPSS
0.54%
41.9th percentile
HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | system_management_homepage | <= 7.5.3.1 | — |
CVSS provenance
nvdv3.07.7HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9963 exim: Possible information disclosure to remote atacker
bugzilla·2016-12-16·CVSS 5.9
CVE-2016-9963 [MEDIUM] CVE-2016-9963 exim: Possible information disclosure to remote atacker
CVE-2016-9963 exim: Possible information disclosure to remote atacker
Under certain circumstances it's possible for remote attacker to leak private information.
Affected versions: 4.69 -> 4.87
Upstream bug:
https://bugs.exim.org/show_bug.cgi?id=1996
CVE assignment:
http://seclists.org/oss-sec/2016/q4/694
Discussion:
Created exim tracking bugs for this issue:
Affects: fedora-all [bug 1405323]
Affects: epel-all [bug 1405324]
---
External Reference:
https://exim.org/static/doc/CVE-2016-9963.txt
---
Statement:
This flaw does not affect the version of Exim shipped with Red Hat Enterprise Linux 5 because it is not built with DKIM (DomainKeys Identified Mail) support.
Bugzilla
CVE-2016-7040 cfme: Incorrect sanitization in regular expression engine
bugzilla·2016-09-12·CVSS 8.8
CVE-2016-7040 [HIGH] CVE-2016-7040 cfme: Incorrect sanitization in regular expression engine
CVE-2016-7040 cfme: Incorrect sanitization in regular expression engine
In ManageIQ product there was found an improper input validation vulnerability in expression engine allowing to trigger code execution. The issue was found to be exploitable both via JSON API, which can be triggered by users authorized with GET/read access to a collection in API, and via UI when filtering on VMs based on regular expression, which can be triggered by users able to view and filter on VMs in UI.
Discussion:
Acknowledgments:
Name: Tim Wade (Red Hat)
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.6
Via RHSA-2016:1996 https://rhn.redhat.com/errata/RHSA-2016-1996.html
2016-03-18
Published