The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/98636 - | |
References | () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04500238 - Vendor Advisory |
Information
Published : 2014-11-14 00:59
Updated : 2024-11-21 02:18
NVD link : CVE-2014-7878
Mitre link : CVE-2014-7878
CVE.ORG link : CVE-2014-7878
JSON object : View
Products Affected
hp
- helion_cloud_development_platform
CWE
CWE-310
Cryptographic Issues