CVE-2018-18593

MEDIUM

HP UCMDB Configuration Manager Remote Directory Traversal and Privileged Information Disclosure

Title source: llm
STIX 2.1

Description

Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities could allow Remote Directory Traversal and Remote Disclosure of Privileged Information

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106374

Scores

CVSS v3 6.5
EPSS 0.0153
EPSS Percentile 81.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-22
Status published
Products (6)
hp/ucmdb_configuration_manager 10.22 (8 CPE variants)
hp/ucmdb_configuration_manager 10.33 (4 CPE variants)
hp/ucmdb_configuration_manager 2018.02
hp/ucmdb_configuration_manager 2018.05
hp/ucmdb_configuration_manager 2018.08
hp/ucmdb_configuration_manager 2018.11
Published Dec 31, 2018
Tracked Since Feb 18, 2026