CVE-2019-5408
MEDIUMHP XP7 Device Manager 7.0.0-00-8.6.1-01 - Unauthenticated Information Exposure via GUI
Title source: llmDescription
Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier than 8.6.1-02 RepMgr if it is installed on the same machine as DevMgr TSMgr if it is installed on the same machine as DevMgr. The resolution is to upgrade to the fixed version as described below or later version of DevMgr 8.6.2-02 or later. RepMgr and TSMgr will be corrected by upgrading DevMgr.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03938en_us
Scores
CVSS v3
6.5
EPSS
0.0055
EPSS Percentile
68.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Details
Status
published
Products (3)
hp/xp7_device_manager
7.0.0-00 - 8.6.1-02
hp/xp7_replication_manager
hp/xp7_tiered_storage_manager
Published
Aug 09, 2019
Tracked Since
Feb 18, 2026