Vulnerability Description
A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Operations Orchestration | <= 10.70 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100588Third Party AdvisoryVDB Entry
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_naVendor Advisory
- https://www.tenable.com/security/research/tra-2017-25
- https://www.tenable.com/security/research/tra-2017-28
- http://www.securityfocus.com/bid/100588Third Party AdvisoryVDB Entry
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_naVendor Advisory
- https://www.tenable.com/security/research/tra-2017-25
- https://www.tenable.com/security/research/tra-2017-28
FAQ
What is CVE-2017-8994?
CVE-2017-8994 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.
How severe is CVE-2017-8994?
CVE-2017-8994 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-8994?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Operations Orchestration.