CVE-2018-6494

Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microfocus:service_manager:9.30:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.31:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.32:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.33:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.34:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.35:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.40:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.41:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.50:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:service_manager:9.51:*:*:*:*:*:*:*

History

21 Nov 2024, 04:10

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/104141 - () http://www.securityfocus.com/bid/104141 -
References () http://www.securitytracker.com/id/1040902 - () http://www.securitytracker.com/id/1040902 -
References () https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158656 - () https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158656 -

07 Nov 2023, 02:59

Type Values Removed Values Added
References (CONFIRM) https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158656 - Vendor Advisory () https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158656 -
References (SECTRACK) http://www.securitytracker.com/id/1040902 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1040902 -
References (BID) http://www.securityfocus.com/bid/104141 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/104141 -

Information

Published : 2018-05-22 18:29

Updated : 2024-11-21 04:10


NVD link : CVE-2018-6494

Mitre link : CVE-2018-6494

CVE.ORG link : CVE-2018-6494


JSON object : View

Products Affected

microfocus

  • service_manager
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')