RULE(RULE ID:321904)

Rule General Information
Release Date: 2019-06-21
Rule Name: HPE Operations Orchestration central-remoting Remote Code Execution Vulnerability (CVE-2017-8994)
Severity:
CVE ID:
Rule Protection Details
Description: A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Others
Reference: SecurityFocusBID:100588
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03767en_us
https://www.tenable.com/security/research/tra-2017-25
https://www.tenable.com/security/research/tra-2017-28
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03767en_us