VulnerabilityModified
CVE-2018-6494
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
MEDIUM 5.4EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- microfocus/service manager
- Source
- security@opentext.com
References
- http://www.securityfocus.com/bid/104141
- http://www.securitytracker.com/id/1040902
- https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158656
- http://www.securityfocus.com/bid/104141
- http://www.securitytracker.com/id/1040902
- https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03158656
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.