cbcvebase.

Hp Oneview vulnerabilities

22 known vulnerabilities affecting hp/oneview.

Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH7MEDIUM11

Vulnerabilities

Page 1 of 2
CVE-2023-30908P2CRITICALCVSS 9.8fixed in 6.60.05≥ 7.0, < 8.52023-09-07
CVE-2023-30908 [CRITICAL] CVE-2023-30908: A remote authentication bypass issue exists in a OneView API. A remote authentication bypass issue exists in a OneView API.
nvd
CVE-2023-30909P2CRITICALCVSS 9.8fixed in 8.30.012023-09-14
CVE-2023-30909 [CRITICAL] CWE-294 CVE-2023-30909: A remote authentication bypass issue exists in some OneView APIs. A remote authentication bypass issue exists in some OneView APIs.
nvd
CVE-2022-28617P3CRITICALCVSS 9.8fixed in 7.02022-05-17
CVE-2022-28617 [CRITICAL] CVE-2022-28617: A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
nvd
CVE-2020-7198P3HIGHCVSS 8.8v5.0v5.00.01+5 more2020-11-06
CVE-2020-7198 [HIGH] CVE-2020-7198: There is a remote escalation of privilege possible for a malicious user that has a OneView account i There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.
nvd
CVE-2022-28616P3CRITICALCVSS 9.8fixed in 7.02022-05-17
CVE-2022-28616 [CRITICAL] CWE-918 CVE-2022-28616: A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
nvd
CVE-2023-50274P3HIGHCVSS 7.8fixed in 8.702024-01-23
CVE-2023-50274 [HIGH] CWE-77 CVE-2023-50274: HPE OneView may allow command injection with local privilege escalation. HPE OneView may allow command injection with local privilege escalation.
nvd
CVE-2022-23698P3HIGHCVSS 7.5fixed in 6.62022-04-04
CVE-2022-23698 [HIGH] CVE-2022-23698: A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView versi A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
nvd
CVE-2023-50275P3HIGHCVSS 7.5fixed in 8.702024-01-23
CVE-2023-50275 [HIGH] CWE-287 CVE-2023-50275: HPE OneView may allow clusterService Authentication Bypass resulting in denial of service. HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
nvd
CVE-2022-23699P3HIGHCVSS 7.8fixed in 6.62022-04-04
CVE-2022-23699 [HIGH] CVE-2022-23699: A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Pr A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
nvd
CVE-2023-28088P3HIGHCVSS 7.8fixed in 6.60.04fixed in 8.22023-04-25
CVE-2023-28088 [HIGH] CWE-522 CVE-2023-28088: An HPE OneView appliance dump may expose SAN switch administrative credentials An HPE OneView appliance dump may expose SAN switch administrative credentials
nvd
CVE-2014-2602P4MEDIUMCVSS 6.5v1.0v1.012014-05-08
CVE-2014-2602 [MEDIUM] CVE-2014-2602: Unspecified vulnerability in HP OneView 1.0 and 1.01 allows remote authenticated users to gain privi Unspecified vulnerability in HP OneView 1.0 and 1.01 allows remote authenticated users to gain privileges via unknown vectors.
nvd
CVE-2023-28089P4HIGHCVSS 7.1fixed in 6.60.04fixed in 8.22023-04-25
CVE-2023-28089 [HIGH] CWE-522 CVE-2023-28089: An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
nvd
CVE-2022-28625P4MEDIUMCVSS 5.5fixed in 6.60.012022-08-31
CVE-2022-28625 [MEDIUM] CWE-532 CVE-2022-28625: A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality, integrity, and availability. To exploit this vulnerability, HPE OneView must be c
nvd
CVE-2022-23697P4MEDIUMCVSS 6.1fixed in 6.62022-04-04
CVE-2022-23697 [MEDIUM] CWE-79 CVE-2022-23697: A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
nvd
CVE-2022-23706P4MEDIUMCVSS 6.1fixed in 7.02022-05-17
CVE-2022-23706 [MEDIUM] CWE-79 CVE-2022-23706: A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
nvd
CVE-2022-23700P4MEDIUMCVSS 5.5fixed in 6.62022-04-04
CVE-2022-23700 [MEDIUM] CVE-2022-23700: A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Pr A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
nvd
CVE-2023-28084P4MEDIUMCVSS 5.5fixed in 6.60.04≥ 7.0, < 8.22023-04-25
CVE-2023-28084 [MEDIUM] CWE-522 CVE-2023-28084: HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
nvd
CVE-2023-28090P4MEDIUMCVSS 5.5fixed in 6.60.04fixed in 8.22023-04-25
CVE-2023-28090 [MEDIUM] CWE-522 CVE-2023-28090: An HPE OneView appliance dump may expose SNMPv3 read credentials An HPE OneView appliance dump may expose SNMPv3 read credentials
nvd
CVE-2023-28087P4MEDIUMCVSS 5.5fixed in 6.60.04fixed in 8.22023-04-25
CVE-2023-28087 [MEDIUM] CWE-522 CVE-2023-28087: An HPE OneView appliance dump may expose OneView user accounts An HPE OneView appliance dump may expose OneView user accounts
nvd
CVE-2023-28091P4MEDIUMCVSS 5.5≥ 7.0, ≤ 8.12023-04-14
CVE-2023-28091 [MEDIUM] CVE-2023-28091: HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in a HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump
nvd
Hp Oneview vulnerabilities | cvebase