« Volver al listado

CVE-2022-37931

Estado: ModificadaAlta (7.8)—

A vulnerability in NetBatch-Plus software allows unauthorized access to the application.

HPE has provided a workaround and fix. Please refer to HPE Security Bulletin

HPESBNS04388

for details.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-37931",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-37931",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-25T20:30:14.876474Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@hpe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "HPE",
          "product": "NetBatch-Plus software",
          "versions": [
            {
              "status": "affected",
              "version": "T9189L01 - T9189L01^ABY"
            },
            {
              "status": "affected",
              "version": "T9189H01 – T9189H01^ABW"
            }
          ],
          "platforms": [
            "HPE NonStop Server"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-11-22T05:15:11.153",
  "references": [
    {
      "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbns04388en_us",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbns04388en_us",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-alert@hpe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in NetBatch-Plus software allows unauthorized access to the application. \n\nHPE has provided a workaround and fix. Please refer to HPE Security Bulletin \n\nHPESBNS04388 \n\nfor details.\n"
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en el software NetBatch-Plus permite el acceso no autorizado a la aplicación. HPE ha proporcionado un workaround. Consulte el boletín de seguridad de HPE HPESBNS04388 para obtener más detalles."
    }
  ],
  "lastModified": "2026-06-17T04:55:43.490",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:nonstop_netbatch-plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5092EAF-D62E-489B-8C2C-2590CBB356DD",
              "versionEndExcluding": "t9189h01\\^abw",
              "versionStartIncluding": "t9189h01"
            },
            {
              "criteria": "cpe:2.3:a:hp:nonstop_netbatch-plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "468AC7D6-1CF2-4376-95EC-AD468A05519B",
              "versionEndExcluding": "t9189l01\\^aby",
              "versionStartIncluding": "t9189l01"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}