CVE Vulnerabilities

CVE-2020-7198

Published: Nov 06, 2020 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

Affected Software

NameVendorStart VersionEnd Version
OneviewHp5.0 (including)5.0 (including)
OneviewHp5.00.01 (including)5.00.01 (including)
OneviewHp5.00.02 (including)5.00.02 (including)
OneviewHp5.2 (including)5.2 (including)
OneviewHp5.3 (including)5.3 (including)
OneviewHp5.4 (including)5.4 (including)
OneviewHp5.20.01 (including)5.20.01 (including)
Synergy_composerHp5.0 (including)5.0 (including)
Synergy_composerHp5.00.01 (including)5.00.01 (including)
Synergy_composerHp5.00.02 (including)5.00.02 (including)
Synergy_composerHp5.2 (including)5.2 (including)
Synergy_composerHp5.3 (including)5.3 (including)
Synergy_composerHp5.4 (including)5.4 (including)
Synergy_composerHp5.20.01 (including)5.20.01 (including)
Synergy_composer_2Hp5.0 (including)5.0 (including)
Synergy_composer_2Hp5.00.01 (including)5.00.01 (including)
Synergy_composer_2Hp5.00.02 (including)5.00.02 (including)
Synergy_composer_2Hp5.2 (including)5.2 (including)
Synergy_composer_2Hp5.3 (including)5.3 (including)
Synergy_composer_2Hp5.4 (including)5.4 (including)
Synergy_composer_2Hp5.20.01 (including)5.20.01 (including)

References