CVE-2019-5408
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/08/2019
Last modified:
24/08/2020
Description
Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier than 8.6.1-02 RepMgr if it is installed on the same machine as DevMgr TSMgr if it is installed on the same machine as DevMgr. The resolution is to upgrade to the fixed version as described below or later version of DevMgr 8.6.2-02 or later. RepMgr and TSMgr will be corrected by upgrading DevMgr.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hp:xp7_device_manager:*:*:*:*:*:*:*:* | 7.0.0-00 (including) | 8.6.1-02 (excluding) |
| cpe:2.3:a:hp:xp7_replication_manager:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hp:xp7_tiered_storage_manager:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



