vendor:
Universal CMDB
by:
Hans-Martin Muench
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Universal CMDB
Affected Version From: UCMDB 10.10
Affected Version To: UCMDB 10.10
Patch Exists: NO
Related CWE: CVE-2014-7883
CPE: 2.3:a:hewlett_packard:universal_cmdb
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Hewlett-Packard UCMDB – JMX-Console Authentication Bypass
A vulnerability in Hewlett-Packard Universal CMDB (UCMDB) allows an attacker to bypass authentication and gain access to the JMX-Console. This vulnerability affects UCMDB 10.10 and other versions might also be affected. The vulnerability is remotely exploitable and has a high impact.
Mitigation:
HP should fix the vulnerability as soon as possible and provide a patch.