Operations Orchestration

Vendor:

First CVE: Oct 26, 2010 · Active for 15 years

11
Total CVEs
More Total CVEs than 90% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Operations Orchestration over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2010
15 years ago
Most Recent CVE
Mar 2, 2018
3,070 days ago

CVE Severity & Scoring

Operations Orchestration11 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (36.4%)
Unknown7 (63.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (36.4%)
High0 (0.0%)
Unknown7 (63.6%)
User Interaction
None4 (36.4%)
Unknown7 (63.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (36.4%)
Unknown7 (63.6%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found.
Feb 15, 20189.837NONO
A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.
Oct 10, 20179.835NONO
Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.
Sep 19, 201210.035NONO
HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java
Mar 22, 20169.829NONO
Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service.
Mar 2, 20187.525NONO
Unspecified vulnerability in HP Operations Orchestration 10.x allows remote attackers to bypass authentication, and obtain sensitive information or modify data, via unknown vectors
Mar 31, 20157.520NONO
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified vic
Nov 23, 20156.818NONO
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspecified victims via unknown vect
Dec 17, 20136.818NONO
Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9.0, when Internet Explorer 6.0 is used, allows remote attackers to inject arbitrary web script or HT
Oct 26, 20104.318NONO
Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Dec 17, 20134.314NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Operations Orchestration

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.026.85.9%00
7.235.11.8%00
7.135.11.8%00
10.5019.86.7%00
10.22.119.86.7%00
10.2219.86.7%00
10.2119.86.7%00
10.2019.86.7%00
10.1019.86.7%00
10.0219.86.7%00
10.0119.86.7%00
10.047.13.8%00