SB2017093005 - Missing Authentication for Critical Function in Oracle Application Performance Management
Published: September 30, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Authentication for Critical Function (CVE-ID: CVE-2017-14350)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnerability could be remotely exploited to allow code execution.
Remediation
Install update from vendor's website.