Lucene search

K
cvelistHpeCVELIST:CVE-2022-28625
HistoryAug 31, 2022 - 3:59 p.m.

CVE-2022-28625

2022-08-3115:59:33
hpe
www.cve.org
hpe oneview
sensitive information
vulnerability
software update

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality, integrity, and availability. To exploit this vulnerability, HPE OneView must be configured with credential access to external repositories. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CNA Affected

[
  {
    "product": "HPE OneView",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to 7.0 or 6.60.01"
      }
    ]
  }
]

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2022-28625