This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Hp First view 2005-06-29
Product Version Control Repository Manager Last view 2018-02-15
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:hp:version_control_repository_manager:1.0.2289.0:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:1.0.2345.0:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:2.0.0.50:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:2.0.1.30:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:1.0.1288.1:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:1.0.2241.0:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:2.1.1.710:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:2.1.1.720:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:1.0.3085.0:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:1.0.3086.0:*:*:*:*:*:*:* 11
cpe:2.3:a:hp:version_control_repository_manager:6.0.1:*:*:*:*:*:*:* 10
cpe:2.3:a:hp:version_control_repository_manager:6.0.2:*:*:*:*:*:*:* 10
cpe:2.3:a:hp:version_control_repository_manager:6.1:*:*:*:*:*:*:* 10
cpe:2.3:a:hp:version_control_repository_manager:*:*:*:*:*:*:*:* 10

Related : CVE

  Date Alert Description
6.5 2018-02-15 CVE-2017-5787

A remote denial of service vulnerability in HPE Version Control Repository Manager (VCRM) in all versions prior to 7.6 was found.

8.8 2018-02-15 CVE-2016-8515

A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

6.5 2018-02-15 CVE-2016-8514

A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

8 2018-02-15 CVE-2016-8513

A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

4 2015-08-26 CVE-2015-5413

HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to gain privileges and obtain sensitive information via unspecified vectors.

6 2015-08-26 CVE-2015-5412

Cross-site request forgery (CSRF) vulnerability in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

6.8 2015-08-26 CVE-2015-5411

HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors.

6.5 2015-08-26 CVE-2015-5410

HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to execute arbitrary code or cause a denial of service via unspecified vectors.

7.5 2015-08-26 CVE-2015-5409

Buffer overflow in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

4.3 2010-10-28 CVE-2010-3994

Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2.1 2005-06-29 CVE-2005-2076

HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.

CWE : Common Weakness Enumeration

%idName
25% (2) CWE-352 Cross-Site Request Forgery (CSRF)
25% (2) CWE-200 Information Exposure
12% (1) CWE-434 Unrestricted Upload of File with Dangerous Type
12% (1) CWE-264 Permissions, Privileges, and Access Controls
12% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
12% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Open Source Vulnerability Database (OSVDB)

id Description
68907 HP Version Control Repository Manager Unspecified XSS
17509 HP VCRM Proxy Server Cleartext Password Disclosure

Information Assurance Vulnerability Management (IAVM)

id Description
2015-B-0106 Multiple Vulnerabilities in HP Version Control Repository Manager
Severity: Category I - VMSKEY: V0061359

Nessus® Vulnerability Scanner

id Description
2017-01-24 Name: An application installed on the remote Windows host is affected by multiple v...
File: hp_version_control_repo_manager_7_6_0_0.nasl - Type: ACT_GATHER_INFO
2017-01-24 Name: An application installed on the remote Linux host is affected by multiple vul...
File: hp_version_control_repo_manager_7_6_0_nix.nasl - Type: ACT_GATHER_INFO
2015-09-04 Name: The remote Windows host has an application installed that is affected by mult...
File: hp_version_control_repo_manager_7_5_0_0.nasl - Type: ACT_GATHER_INFO
2015-09-04 Name: The remote Linux host has an application installed that is affected by multip...
File: hp_version_control_repo_manager_7_5_0_nix.nasl - Type: ACT_GATHER_INFO