CVE-2018-6493

EUVD-2018-18249
SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injection.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
microfocusCNA
8.7 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
hpnetwork_operations_management_ultimate
2017.07
hpnetwork_operations_management_ultimate
2017.11
hpnetwork_operations_management_ultimate
2018.02
hpnetwork_automation
10.00
hpnetwork_automation
10.10
hpnetwork_automation
10.11
hpnetwork_automation
10.20
hpnetwork_automation
10.30
hpnetwork_automation
10.40
hpnetwork_automation
10.50
𝑥
= Vulnerable software versions