CVE-2014-7883

HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:universal_configuration_management_database:9.05:*:*:*:*:*:*:*
cpe:2.3:a:hp:universal_configuration_management_database:10.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:universal_configuration_management_database:10.11:*:*:*:*:*:*:*

History

21 Nov 2024, 02:18

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/867593 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/867593 - Third Party Advisory, US Government Resource
References () http://www.securitytracker.com/id/1031688 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1031688 - Third Party Advisory, VDB Entry
References () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04553906 - Not Applicable () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04553906 - Not Applicable

Information

Published : 2015-02-15 20:59

Updated : 2024-11-21 02:18


NVD link : CVE-2014-7883

Mitre link : CVE-2014-7883

CVE.ORG link : CVE-2014-7883


JSON object : View

Products Affected

hp

  • universal_configuration_management_database
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor