SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-13984

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal.

MEDIUM 6.5EPSS 2.01%

Does this matter?

Lower severity and a low EPSS score (2.01%). Track it; it rarely justifies an emergency change on its own.

Description

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
2.01% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
hp/bsm platform application performance management system health
Source
security@opentext.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.