CVE-2014-7878

The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:helion_cloud_development_platform:1.0:*:*:*:commercial:*:*:*
cpe:2.3:a:hp:helion_cloud_development_platform:1.0:*:*:*:community:*:*:*

History

21 Nov 2024, 02:18

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/98636 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/98636 -
References () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04500238 - Vendor Advisory () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04500238 - Vendor Advisory

Information

Published : 2014-11-14 00:59

Updated : 2024-11-21 02:18


NVD link : CVE-2014-7878

Mitre link : CVE-2014-7878

CVE.ORG link : CVE-2014-7878


JSON object : View

Products Affected

hp

  • helion_cloud_development_platform
CWE
CWE-310

Cryptographic Issues