cbcvebase.

Hp System Management Homepage vulnerabilities

77 known vulnerabilities affecting hp/system_management_homepage.

Total CVEs
77
CISA KEV
2
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH14MEDIUM48LOW5

Vulnerabilities

Page 3 of 4
CVE-2017-12552P4MEDIUMCVSS 5.6fixed in 7.6.12018-02-15
CVE-2017-12552 [MEDIUM] CVE-2017-12552: A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2017-12553P4MEDIUMCVSS 5.6fixed in 7.6.12018-02-15
CVE-2017-12553 [MEDIUM] CVE-2017-12553: A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2014-2642P4MEDIUMCVSS 4.3≤ 7.3v7.0+3 more2014-10-02
CVE-2014-2642 [MEDIUM] CWE-20 CVE-2014-2642: HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attac HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2013-2363P4MEDIUMCVSS 5.0≤ 7.2v7.0+1 more2013-07-22
CVE-2013-2363 [MEDIUM] CVE-2013-2363: HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive informa HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2356.
nvd
CVE-2013-2356P4MEDIUMCVSS 5.0≤ 7.2v7.0+1 more2013-07-22
CVE-2013-2356 [MEDIUM] CVE-2013-2356: HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive informa HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2363.
nvd
CVE-2015-2134P4MEDIUMCVSS 6.0≤ 7.4.02015-07-21
CVE-2015-2134 [MEDIUM] CWE-352 CVE-2015-2134: Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.5.0 Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2014-2641P4MEDIUMCVSS 6.0≤ 7.3v7.0+3 more2014-10-02
CVE-2014-2641 [MEDIUM] CWE-352 CVE-2014-2641: Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 al Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2017-12548P4MEDIUMCVSS 5.6fixed in 7.6.12018-02-15
CVE-2017-12548 [MEDIUM] CVE-2017-12548: A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2017-12547P4MEDIUMCVSS 5.6fixed in 7.6.12018-02-15
CVE-2017-12547 [MEDIUM] CVE-2017-12547: A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2013-4846P4MEDIUMCVSS 5.0≤ 7.2.2v2.0.0+72 more2014-03-14
CVE-2013-4846 [MEDIUM] CVE-2013-4846: Unspecified vulnerability in HP System Management Homepage (SMH) before 7.3 allows remote attackers Unspecified vulnerability in HP System Management Homepage (SMH) before 7.3 allows remote attackers to obtain sensitive information via unknown vectors.
nvd
CVE-2016-4393P4MEDIUMCVSS 5.4≤ 7.5.5.02016-10-28
CVE-2016-4393 [MEDIUM] CWE-79 CVE-2016-4393: HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensiti HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.
nvd
CVE-2017-12549P4MEDIUMCVSS 5.6fixed in 7.6.12018-02-15
CVE-2017-12549 [MEDIUM] CWE-287 CVE-2017-12549: A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2017-12546P4MEDIUMCVSS 5.6fixed in 7.6.12018-02-15
CVE-2017-12546 [MEDIUM] CWE-119 CVE-2017-12546: A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux versio A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2014-2640P4MEDIUMCVSS 4.3≤ 7.3v7.0+3 more2014-10-02
CVE-2014-2640 [MEDIUM] CWE-79 CVE-2014-2640: Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows re Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2007-3062P4MEDIUMCVSS 4.3v2.0.0v2.0.1+3 more2007-06-06
CVE-2007-3062 [MEDIUM] CVE-2007-3062: Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.2 running Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.2 running on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2017-12550P4MEDIUMCVSS 5.6fixed in 7.6.12018-02-15
CVE-2017-12550 [MEDIUM] CVE-2017-12550: A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Li A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2008-1663P4MEDIUMCVSS 4.3v2.1.10v2.1.112008-07-09
CVE-2008-1663 [MEDIUM] CWE-79 CVE-2008-1663: Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) 2.1.10 and 2.1.11 on Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) 2.1.10 and 2.1.11 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2008-4411P4MEDIUMCVSS 4.3≤ 2.1.12-200v2.0.0+29 more2008-10-13
CVE-2008-4411 [MEDIUM] CVE-2008-4411: Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.15.210 on Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.15.210 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-1663.
nvd
CVE-2010-1034P4MEDIUMCVSS 4.6v6.02010-04-23
CVE-2010-1034 [MEDIUM] CVE-2010-1034: Unspecified vulnerability in HP System Management Homepage (SMH) 6.0 before 6.0.0-95 on Linux, and 6 Unspecified vulnerability in HP System Management Homepage (SMH) 6.0 before 6.0.0-95 on Linux, and 6.0 before 6.0.0.96 on Windows, allows remote authenticated users to obtain sensitive information, modify data, and cause a denial of service via unknown vectors.
nvd
CVE-2008-4413P4MEDIUMCVSS 6.2≤ 2.2.6v2.0.0+32 more2008-11-04
CVE-2008-4413 [MEDIUM] CWE-264 CVE-2008-4413: Unspecified vulnerability in HP System Management Homepage (SMH) 2.2.6 and earlier on HP-UX B.11.11 Unspecified vulnerability in HP System Management Homepage (SMH) 2.2.6 and earlier on HP-UX B.11.11 and B.11.23, and SMH 2.2.6 and 2.2.8 and earlier on HP-UX B.11.23 and B.11.31, allows local users to gain "unauthorized access" via unknown vectors, possibly related to temporary file permissions.
nvd
Hp System Management Homepage vulnerabilities | cvebase