« Volver al listado

CVE-2017-14353

Estado: ModificadaAlta (8.8)—

A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, could be remotely exploited to allow code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-14353",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@opentext.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-05T15:29:00.213",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/101251",
      "source": "security@opentext.com"
    },
    {
      "url": "https://softwaresupport.hpe.com/km/KM02977984",
      "source": "security@opentext.com"
    },
    {
      "url": "https://www.auscert.org.au/bulletins/53150",
      "source": "security@opentext.com"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2017-32",
      "source": "security@opentext.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/101251",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://softwaresupport.hpe.com/km/KM02977984",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.auscert.org.au/bulletins/53150",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2017-32",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, could be remotely exploited to allow code execution."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de ejecución remota de código en HP UCMDB Foundation Software en sus versiones 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32 y 10.33 que podrían explotarse de forma remota para permitir la ejecución de código."
    }
  ],
  "lastModified": "2026-06-17T01:06:00.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1125157-FC5F-4F07-81A7-D2AD2B7957AE"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF124634-2A30-4B07-A33E-BB4FDBC4E9C8"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78860693-A83D-401F-9517-C60D9097AE6B"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2717F1C2-8E27-4181-B5C0-6D3932EDBDF6"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17CB4F73-6839-4370-A49E-E08D0D604947"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBABCE4D-D4D7-46FD-8244-5FD65D61C558"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A1718D3-3166-4523-A2FF-4B9D9EF0F589"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.32:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17A7BB86-AB7E-413E-B263-D28A8D978293"
            },
            {
              "criteria": "cpe:2.3:a:hp:ucmdb_foundation_software:10.33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9CF09FB-4AE6-4780-A08E-41317BD47700"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@opentext.com"
}