SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-13985

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclosure of information.

MEDIUM 6.5EPSS 2.69%

Does this matter?

Lower severity and a low EPSS score (2.69%). Track it; it rarely justifies an emergency change on its own.

Description

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclosure of information.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
2.69% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
hp/bsm platform application performance management system health
Source
security@opentext.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.