SB2017111305 - Multiple vulnerabilities in HPE Matrix Operating Environment
Published: November 13, 2017 Updated: November 20, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2017-8970)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.The weakness exists due to unknown error. A remote attacker can trick the victim into visiting a specially crafted website and gain access to arbitrary data.
2) Click-jacking attack (CVE-ID: CVE-2017-8971)
The vulnerability allows a remote attacker to perform click-jacking attacks.
The vulnerability exists due to unknown error. A remote attacker can perform click-jacking attack.
3) Click-jacking attack (CVE-ID: CVE-2017-8972)
The vulnerability allows a remote attacker to perform click-jacking attacks.
The vulnerability exists due to unknown error. A remote attacker can perform click-jacking attack.
4) Improper input validation (CVE-ID: CVE-2017-8973)
The vulnerability allows a remote attacker to modify information on the target system.
The vulnerability exists due to improper validation of user-supplied input. A remote attacker can trick the victim into opening a specially crafted input and have unspecified impact.
Remediation
Install update from vendor's website.