Vulnerability Description
There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Oneview | 5.0 |
| Hp | Synergy Composer | 5.0 |
| Hp | Synergy Composer 2 | 5.0 |
References
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
FAQ
What is CVE-2020-7198?
CVE-2020-7198 is a vulnerability with a CVSS score of 8.8 (HIGH). There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to ...
How severe is CVE-2020-7198?
CVE-2020-7198 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7198?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Oneview, Hp Synergy Composer, Hp Synergy Composer 2.