CVE-2014-7883 describes an information disclosure vulnerability in HP Universal CMDB (UCMDB) Probe versions 9.05, 10.01, and 10.11. This flaw allows remote attackers to obtain sensitive information by exploiting the enabled HTTP TRACE method to read response headers. With a CVSS score of 5.0 (medium severity), this vulnerability is easily exploitable over the network with low attack complexity and no authentication required, potentially leading to partial confidentiality impact. While there is no known active exploitation or Metasploit/Nuclei modules, an ExploitDB entry for an authentication bypass in HP UCMDB exists (though not directly for TRACE), and the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.05CPE matchmatch criteria | cpe:2.3:a:hp:universal_configuration_management_database:9.05:*:*:*:*:*:*:* | ||
10.01CPE matchmatch criteria | cpe:2.3:a:hp:universal_configuration_management_database:10.01:*:*:*:*:*:*:* | ||
10.11CPE matchmatch criteria | cpe:2.3:a:hp:universal_configuration_management_database:10.11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.