« Volver al listado

CVE-2017-14351

Estado: ModificadaCrítica (9.8)—

A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-14351",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@opentext.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-09-30T01:29:01.523",
  "references": [
    {
      "url": "https://softwaresupport.hpe.com/km/KM02968622",
      "source": "security@opentext.com"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2017-32",
      "source": "security@opentext.com"
    },
    {
      "url": "https://softwaresupport.hpe.com/km/KM02968622",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2017-32",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow code execution."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad de seguridad potencial en las versiones 10.10, 10.11, 10.20, 10.21, 10.22 y 10.23 de HP UCMDB Configuration Manager. Estas vulnerabilidades podrían explotarse de forma remota para permitir la ejecución de código."
    }
  ],
  "lastModified": "2026-06-17T01:06:00.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_configuration_manager:10.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51748783-95F1-400A-A435-12D1F4A1312E"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_configuration_manager:10.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3837E366-A291-4E93-9AC7-595BF661CE42"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_configuration_manager:10.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97E3B18E-18CE-42C5-BDCC-93A339C2E80B"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_configuration_manager:10.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4FA4110-8DB1-4CC1-A768-F33E91BB5AD3"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00348879-766F-4CBA-9761-AE4E258CA7EB"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_configuration_manager:10.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4A06A8A-739A-4240-9AF6-080A2D7B4A4D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@opentext.com"
}