ID

VAR-201808-0950


CVE

CVE-2018-7069


TITLE

HPE CentralView Fraud Risk Management Vulnerabilities in authentication

Trust: 0.8

sources: JVNDB: JVNDB-2018-009002

DESCRIPTION

HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version

Trust: 1.62

sources: NVD: CVE-2018-7069 // JVNDB: JVNDB-2018-009002

AFFECTED PRODUCTS

vendor:hpmodel:centralview fraud risk managementscope:ltversion:6.1

Trust: 1.0

vendor:hewlett packardmodel:hpe centralview fraud risk managementscope:ltversion:cv 6.1

Trust: 0.8

sources: JVNDB: JVNDB-2018-009002 // NVD: CVE-2018-7069

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7069
value: HIGH

Trust: 1.0

NVD: CVE-2018-7069
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201808-170
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2018-7069
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2018-7069
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: JVNDB: JVNDB-2018-009002 // CNNVD: CNNVD-201808-170 // NVD: CVE-2018-7069

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.8

sources: JVNDB: JVNDB-2018-009002 // NVD: CVE-2018-7069

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201808-170

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201808-170

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-009002

PATCH

title:hpesbmu03837en_usurl:https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03837en_us

Trust: 0.8

title:HPE CentralView Fraud Risk Management Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=83976

Trust: 0.6

sources: JVNDB: JVNDB-2018-009002 // CNNVD: CNNVD-201808-170

EXTERNAL IDS

db:NVDid:CVE-2018-7069

Trust: 2.4

db:JVNDBid:JVNDB-2018-009002

Trust: 0.8

db:CNNVDid:CNNVD-201808-170

Trust: 0.6

sources: JVNDB: JVNDB-2018-009002 // CNNVD: CNNVD-201808-170 // NVD: CVE-2018-7069

REFERENCES

url:https://support.hpe.com/hpsc/doc/public/display?doclocale=en_us&docid=emr_na-hpesbmu03837en_us

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7069

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7069

Trust: 0.8

url:https://support.hpe.com/hpsc/doc/public/display?doclocale=en_us&docid=emr_na-hpesbmu03837en_us

Trust: 0.6

sources: JVNDB: JVNDB-2018-009002 // CNNVD: CNNVD-201808-170 // NVD: CVE-2018-7069

SOURCES

db:JVNDBid:JVNDB-2018-009002
db:CNNVDid:CNNVD-201808-170
db:NVDid:CVE-2018-7069

LAST UPDATE DATE

2024-11-23T23:12:03.830000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2018-009002date:2018-11-05T00:00:00
db:CNNVDid:CNNVD-201808-170date:2018-08-07T00:00:00
db:NVDid:CVE-2018-7069date:2024-11-21T04:11:35.890

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2018-009002date:2018-11-05T00:00:00
db:CNNVDid:CNNVD-201808-170date:2018-08-07T00:00:00
db:NVDid:CVE-2018-7069date:2018-08-06T20:29:01.837