CVE-2018-18593

Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities could allow Remote Directory Traversal and Remote Disclosure of Privileged Information
References
Link Resource
https://softwaresupport.softwaregrp.com/doc/KM03309650 Vendor Advisory
http://www.securityfocus.com/bid/106374 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:ucmdb_configuration_manager:10.33:cup3:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:cup1:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:cup6:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:*:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:2018.02:*:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:2018.05:*:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:2018.08:*:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:2018.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:cup2:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:cup3:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:cup4:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.33:cup1:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.33:cup2:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.33:*:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:cup5:*:*:*:*:*:*
cpe:2.3:a:hp:ucmdb_configuration_manager:10.22:cup7:*:*:*:*:*:*

Information

Published : 2018-12-31 07:29

Updated : 2019-10-09 16:37


NVD link : CVE-2018-18593

Mitre link : CVE-2018-18593


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

hp

  • ucmdb_configuration_manager