Required CVE Record Information
Description
The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.
References 3 Total
- h20564.www2.hp.com: SSRT101812 vendor-advisory
- exchange.xforce.ibmcloud.com: hp-helion-cve20147878-unauth-access(98636) vdb-entry
- h20564.www2.hp.com: HPSBMU03190 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- h20564.www2.hp.com: SSRT101812 vendor-advisoryx_transferred
- exchange.xforce.ibmcloud.com: hp-helion-cve20147878-unauth-access(98636) vdb-entryx_transferred
- h20564.www2.hp.com: HPSBMU03190 vendor-advisoryx_transferred