« Volver al listado

CVE-2017-14350

Estado: ModificadaCrítica (9.8)—

A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnerability could be remotely exploited to allow code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-14350",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@opentext.com",
      "affectedData": [
        {
          "vendor": "Micro Focus",
          "product": "HPE Application Performance Management (APM)",
          "versions": [
            {
              "status": "affected",
              "version": "9.26"
            },
            {
              "status": "affected",
              "version": "9.30"
            },
            {
              "status": "affected",
              "version": "9.40"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-09-30T01:29:01.490",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100988",
      "source": "security@opentext.com"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-17-825/",
      "source": "security@opentext.com"
    },
    {
      "url": "https://softwaresupport.hpe.com/km/KM02960811",
      "source": "security@opentext.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/100988",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-17-825/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://softwaresupport.hpe.com/km/KM02960811",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnerability could be remotely exploited to allow code execution."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad de seguridad potencial en HPE Application Performance Management (BSM) Platform en versiones 9.26, 9.30 y 9.40. La vulnerabilidad podría explotarse de forma remota para permitir la ejecución de código."
    }
  ],
  "lastModified": "2026-06-17T01:06:00.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:application_performance_management:9.26:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51AF14AC-72C5-4C3B-B828-5F941B085A4E"
            },
            {
              "criteria": "cpe:2.3:a:hp:application_performance_management:9.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5842D8D7-48E7-4126-9EA9-76B877DC176C"
            },
            {
              "criteria": "cpe:2.3:a:hp:application_performance_management:9.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82283FBB-87D2-4C27-9770-3B484F60C0F4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@opentext.com"
}