Back to Database
Status published
Medium
CVE-2016-4393
HPE System Management Homepage before v7.6 allows "remote authenticated" attackers...
Vulnerability Description
HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-4393
Credits & Attribution
No credits recorded in the NVD database.
References
More from HPE
View All →CVE-2023-50271
HP-UX System Management Homepage, Disclosure of Information
High
7.2
CVE-2023-28083
Potential Cross-Site scripting vulnerability in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4).
High
8.3
CVE-2022-37931
A vulnerability in NetBatch-Plus software allows unauthorized access to the application
High
7.3
CVE-2020-7135
A potential security vulnerability has been identified in the disk...
High
7.8
CVE-2019-12000
HPE has found a potential Remote Access Restriction Bypass in...
Medium
6.6
Affected Vendor
Affected Software
HPE System Management Homepage before v7.6
Vulnerable Versions:
HPE System Management Homepage before v7.6
Timeline
Official Publish:
October 28th, 2016
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.