Hp Performance Center vulnerabilities

10 known vulnerabilities affecting hp/performance_center.

Total CVEs
10
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2017-8953MEDIUMCVSS 5.4≤ 12.532018-02-15
CVE-2017-8953 [MEDIUM] CWE-79 CVE-2017-8953: A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Perfo A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Performance Center version v12.53 and earlier was found.
nvd
CVE-2017-14359MEDIUMCVSS 5.4v12.202017-11-03
CVE-2017-14359 [MEDIUM] CWE-79 CVE-2017-14359: A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting.
nvd
CVE-2017-5789CRITICALCVSS 9.8≤ 12.532017-10-11
CVE-2017-5789 [CRITICAL] CWE-119 CVE-2017-5789: HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote att HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified vectors. At least in LoadRunner, this is a libxdrutil.dll mxdr_string heap-based buffer overflow.
nvd
CVE-2016-4382HIGHCVSS 8.3v11.52v12.00+3 more2016-09-21
CVE-2016-4382 [HIGH] CWE-264 CVE-2016-4382: HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass inten HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to a "remote user validation failure" issue.
nvd
CVE-2016-4384HIGHCVSS 8.6≤ 12.202016-09-21
CVE-2016-4384 [HIGH] CVE-2016-4384: HPE Performance Center before 12.50 and LoadRunner before 12.50 allow remote attackers to cause a de HPE Performance Center before 12.50 and LoadRunner before 12.50 allow remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2016-4360CRITICALCVSS 9.1v11.52v12.00+3 more2016-06-08
CVE-2016-4360 [CRITICAL] CVE-2016-4360: web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 1 web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 d
nvd
CVE-2016-4359CRITICALCVSS 9.8v11.52v12.00+3 more2016-06-08
CVE-2016-4359 [CRITICAL] CWE-119 CVE-2016-4359: Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attack
nvd
CVE-2016-4361HIGHCVSS 7.5v11.52v12.00+3 more2016-06-08
CVE-2016-4361 [HIGH] CVE-2016-4361: HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through pa HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allow remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2015-6857HIGHCVSS 7.2v11.52v12.00+3 more2015-11-26
CVE-2015-6857 [HIGH] CVE-2015-6857: Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-3138.
nvd
CVE-2010-1549CRITICALCVSS 10.0PoC≤ 9.02010-05-07
CVE-2010-1549 [CRITICAL] CVE-2010-1549: Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.
nvd