CVE-2016-4371

high-risk
Published 2016-06-19

HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request components.

Do I need to act?

-
0.07% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.0/10 High
NETWORK / LOW complexity

Affected Products (20)

Service Manager
Service Manager
Service Manager
Service Manager Mobility
Service Manager Mobility
Service Manager Mobility
Service Manager Mobility
Service Manager Server
Service Manager Server
Service Manager Server
Service Manager Server
Service Manager Server
Service Manager Server
Service Manager Service Request Catalog
Service Manager Service Request Catalog
Service Manager Service Request Catalog
Service Manager Service Request Catalog
Service Manager Service Request Catalog
Service Manager Web Client
Service Manager Web Client

Affected Vendors

Hp
53
/ 100
high-risk
Severity 28/34 · Critical
Exploitability 0/34 · Minimal
Exposure 25/34 · High