« Back to list

CVE-2014-2645

Status: ModifiedMedium (4.3)—

HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to conduct clickjacking attacks via unknown vectors.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2014-2645",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "hp-security-alert@hp.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-10-05T01:55:08.780",
  "references": [
    {
      "url": "http://www.securitytracker.com/id/1030970",
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04468121",
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1030970",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04468121",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to conduct clickjacking attacks via unknown vectors."
    },
    {
      "lang": "es",
      "value": "HP Systems Insight Manager (SIM) anterior a 7.4 permite a atacantes remotos realizar ataques de clickjacking a través de vectores desconocidos."
    }
  ],
  "lastModified": "2026-06-17T00:06:58.047",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:systems_insight_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAE6414D-10E0-4D10-A8D5-EF1D3163C2FD",
              "versionEndIncluding": "7.3"
            },
            {
              "criteria": "cpe:2.3:a:hp:systems_insight_manager:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A9BB3E0-9E80-49EC-A40E-00217C320E7A"
            },
            {
              "criteria": "cpe:2.3:a:hp:systems_insight_manager:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5DBAFB2-819A-490F-ADF4-0FCFC09C7859"
            },
            {
              "criteria": "cpe:2.3:a:hp:systems_insight_manager:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAE9B61A-A75E-492E-87BC-BC10241AD8D0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "hp-security-alert@hp.com"
}