HPE OneView
1827281 Members
2413 Online
109717 Solutions
New Discussion

Re: HPE OneView Security Update

 
Thaufique_Mod
Moderator

HPE OneView Security Update

VULNERABILITY SUMMARY

Potential security vulnerabilities have been identified in Hewlett Packard Enterprise OneView Software. These vulnerabilities could be exploited allowing a remote attacker to cause a denial of service, code execution or source code disclosure, information disclosure, server-side request forgery (SSRF), and local script execution.

Click the link below from HPE Support Center to get detailed information:

HPESBGN04853 rev.1 - HPE OneView, Multiple Local and Remote Vulnerabilities



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
3 REPLIES 3
tirtul
Occasional Advisor

Re: HPE OneView Security Update

Given the severity of the vulnerability, will workarounds or patches be made available for older releases that some may have for legacy systems?

DanCernese
HPE Pro

Re: HPE OneView Security Update

Product manage has shared in our partner-facing slack channel that there are no plans to update prior releases at this time.

 



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
Kearawill
Visitor

Re: HPE OneView Security Update

Thanks for the heads-up. Important reminder to stay on top of updates — especially with vulnerabilities like SSRF and code execution in the mix. Will review the advisory and patch ASAP.

Keara will