CVE-2014-7883 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 37% (pctl 98)
Patch early
A public exploit exists.
Description
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 37.02% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-02-15 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| hp | universal configuration management database |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass | 2015-02-03 |
References
- http://www.kb.cert.org/vuls/id/867593
- http://www.securitytracker.com/id/1031688
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04553906
- http://www.kb.cert.org/vuls/id/867593
- http://www.securitytracker.com/id/1031688
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04553906
→ the Explorer · watch your stack · NVD