CVE-2016-2015

Severity
7.1HIGH
EPSS
0.1%
top 67.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 17

Description

HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-54x6-hj78-x95f: HPE System Management Homepage before 72022-05-17
GHSA
Spoofing attack due to unvalidated KDC in node-krb52020-09-01
CVEList
CVE-2016-2015: HPE System Management Homepage before 72016-05-14

💥Exploits & PoCs

2
Exploit-DB
glibc - 'getaddrinfo' Remote Stack Buffer Overflow2016-09-06
Exploit-DB
DropBearSSHD 2015.71 - Command Injection2016-03-03

📋Vendor Advisories

2
Red Hat
salt: local_batch client external authentication not respected2017-01-20
Red Hat
php: Use After Free in unserialize()2016-12-08

🕵️Threat Intelligence

2
Fortinet
Zimbra Collaboration XSS Vulnerability: Be Careful If You're Using Zimbra Email2016-01-31
Unit42
NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan2016-01-21

💬Community

6
Bugzilla
CVE-2016-4472 expat: Undefined behavior and pointer overflows2016-06-09
Bugzilla
CVE-2016-1181 struts: Vulnerability in ActionForm allows unintended remote operations against components on server memory2016-06-07
Bugzilla
CVE-2015-7579 rubygem-rails-html-sanitizer: XSS vulnerability in Action View's strip_tags function2016-01-26
Bugzilla
CVE-2015-8778 glibc: Integer overflow in hcreate and hcreate_r2016-01-20
Bugzilla
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c2015-12-28