HP
HP Network Automation: vulnerabilidades y CVE
HP Network Automation tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-6493 | Alta (8.8) | 2.0% | — | 22 may 2018 | SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely… |
| CVE-2018-6492 | Media (6.1) | 1.6% | — | 22 may 2018 | Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30,… |
| CVE-2017-5814 | Crítica (9.8) | 8.7% | — | 15 feb 2018 | A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. |
| CVE-2017-5813 | Media (6.3) | 1.9% | — | 15 feb 2018 | A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. |
| CVE-2017-5812 | Alta (7.5) | 5.3% | — | 15 feb 2018 | A remote sql information disclosure vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. |
| CVE-2017-5811 | Alta (7.5) | 17% | — | 15 feb 2018 | A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. |
| CVE-2017-5810 | Crítica (9.8) | 4.7% | — | 15 feb 2018 | A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. |
| CVE-2016-8511 | Crítica (9.8) | 15% | — | 15 feb 2018 | A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was found. |
| CVE-2016-4386 | Alta (7.8) | 0.50% | — | 29 sept 2016 | HPE Network Automation Software 10.10 allows local users to write to arbitrary files via unspecified vectors. |
| CVE-2016-4385 | Alta (7.3) | 4.4% | — | 29 sept 2016 | The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to… |
| CVE-2016-1989 | Crítica (9.8) | 11% | — | 15 mar 2016 | HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than… |
| CVE-2016-1988 | Crítica (9.8) | 11% | — | 15 mar 2016 | HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than… |
| CVE-2014-2646 | Alta (7.2) | 0.62% | — | 10 oct 2014 | Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictions via unknown vectors. |
| CVE-2011-4790 | Alta (9.3) | 9.0% | — | 2 feb 2012 | Unspecified vulnerability in HP Network Automation 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to execute arbitrary code via unknown vectors. |
| CVE-2011-2403 | Media (6.5) | 2.0% | — | 1 ago 2011 | SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2011-2402 | Media (4.3) | 3.1% | — | 1 ago 2011 | Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2011-1725 | Media (5) | 2.4% | — | 27 abr 2011 | Unspecified vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to obtain sensitive information via unknown vectors. |