{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T20:36:43.795","vulnerabilities":[{"cve":{"id":"CVE-2019-5408","sourceIdentifier":"security-alert@hpe.com","published":"2019-08-09T18:15:12.697","lastModified":"2026-06-17T02:37:38.440","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier than 8.6.1-02 RepMgr if it is installed on the same machine as DevMgr TSMgr if it is installed on the same machine as DevMgr. The resolution is to upgrade to the fixed version as described below or later version of DevMgr 8.6.2-02 or later. RepMgr and TSMgr will be corrected by upgrading DevMgr."},{"lang":"es","value":"Los productos Command View Advanced Edition (CVAE) contienen una vulnerabilidad que podría exponer la información de configuración de hosts y sistemas de almacenamiento administrados mediante el servidor Device Manager. Este problema es debido a una vulnerabilidad en la GUI del Administrador de Dispositivos. Los siguientes productos están afectados. DevMgr versiones 7.0.0-00 y anteriores a 8.6.1-02, RepMgr si está instalado en el mismo equipo que DevMgr, TSMgr si está instalado en el mismo equipo que DevMgr. La resolución es actualizar a versión corregida como se describe a continuación o versión posterior de DevMgr 8.6.2-02 o posterior. RepMgr y TSMgr serán corregidos mediante la actualización de DevMgr."}],"affected":[{"source":"security-alert@hpe.com","affectedData":[{"vendor":"Hewlett Packard Enterprise (HPE)","product":"HP XP7 CVAE","versions":[{"version":"earlier than 8.6.2-02","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:xp7_device_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0-00","versionEndExcluding":"8.6.1-02","matchCriteriaId":"5CF4D741-993D-4FE0-8015-B65D2181EEA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:xp7_replication_manager:-:*:*:*:*:*:*:*","matchCriteriaId":"EF97AE2C-15F0-4F69-A836-EB12DFE0947F"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:xp7_tiered_storage_manager:-:*:*:*:*:*:*:*","matchCriteriaId":"C074B066-8E86-4D42-AF1A-37F88F72FD33"}]}]}],"references":[{"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03938en_us","source":"security-alert@hpe.com","tags":["Vendor Advisory"]},{"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03938en_us","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}