CVE-2019-19539

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
27/01/2020
Last modified:
07/02/2020

Description

An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hp:web_viewpoint_t0320:*:*:*:*:*:*:*:* t0320h01\^abo (including) t0320h01\^aby (including)
cpe:2.3:a:hp:web_viewpoint_t0320:*:*:*:*:*:*:*:* t0320l01\^abp (including) t0320l01\^abz (including)
cpe:2.3:a:hp:web_viewpoint_t0952:*:*:*:*:plus:*:*:* t0952h01\^aag (including) t0952h01\^aaq (including)
cpe:2.3:a:hp:web_viewpoint_t0952:*:*:*:*:plus:*:*:* t0952l01\^aah (including) t0952l01\^aar (including)
cpe:2.3:a:hp:web_viewpoint_t0986:*:*:*:*:enterprise:*:*:* t0320l01\^abp (including) t0320l01\^abz (including)
cpe:2.3:a:hp:web_viewpoint_t0986:*:*:*:*:enterprise:*:*:* t0986h01 (including) t0986h01\^aae (including)