HPE Alert
13919Warning Date
Severity Level
Warning Number
Target Sector
25 May, 2022
● High
2022-4880
All
HPE has released a security update to address several vulnerabilities in the following products:
- installer of HPE Version Control Repository Manager
- IceWall modules:
- IceWall Identity Manager 6.0 (Windows/Oracle JDK 17.0.2)
- IceWall Gen11 Password Reset Option (Windows/Oracle JDK 17.0.2)
- IceWall MFA 4.0 SMS OTP Option (Windows/Oracle JDK 17.0.2)
- IceWall MFA 4.0 FIDO2 Option (Windows/Oracle JDK 17.0.2)
- IceWall MFA 4.0 Mail OTP Option (Windows/Oracle JDK 17.0.2)
- IceWall Federation 4.0 OIDC Social Login (Windows/Oracle JDK 17.0.2)
- IceWall Federation 4.0 OIDC/OAuth OP AS (Windows/Oracle JDK 17.0.2)
An attacker could exploit these vulnerabilities by doing the following:
- Disclosure of Information
- Escalation of Privilege
The CERT team encourages users to review HPE security advisory and apply the necessary updates: