Security Advisory usd AG

Security Advisory on Micro Focus HPE Operations Agent 12.04.006

1. April 2022

Our HeroLab analysts have performed a security analysis on the product HPE Operations Agent by Micro Focus. They identified an XXE (XML eXternal Entity) vulnerability in 2019. Out of consideration for a group of customers, we are only disclosing the vulnerability now.

The disclosure of the vulnerabilities is in accordance with usd HeroLab's Responsible Disclosure Policy. Detailed information about this advisory can be found here.

About usd HeroLab Security Advisories

In order to protect businesses against hackers and criminals, we must ensure that our skills and knowledge are up to date at all times. Therefore, security research is just as important to our work as is building up a security community to promote an exchange of knowledge. After all, more security can only be achieved if many people take on the task.

We analyze attack scenarios, which are changing constantly, and publish a series of Security Advisories on current vulnerabilities and security issues – always in line with our Responsible Disclosure Policy.

Always in the name of our mission: “more security.”

Also interesting:

Part-IS: The 7 Most Important Questions

Part-IS: The 7 Most Important Questions

Civil aviation consists of a complex network of numerous interrelated systems that are increasingly becoming the target of cyber attacks. Part-IS is intended to oblige the organizations involved to take effective measures to protect themselves against information...

PCI DSS: PCI Council Releases SAQs for Version 4.0.1

PCI DSS: PCI Council Releases SAQs for Version 4.0.1

This week, the PCI Security Standards Council (PCI SSC) announced that it published the Self-Assessment Questionnaires (SAQs) for PCI DSS v4.0.1. [See the PCI SSC Bulletin] With the help of SAQs, eligible merchants and service providers can prove their compliance with...

women@usd. By and for Women in Cyber Security

women@usd. By and for Women in Cyber Security

You can read a lot about the lack of women in technical professions. At usd, we are very fortunate to have plenty of great female colleagues in our ranks. But we also value the exchange with each other. This year, we launched the internal “women@usd” network for this...

Categories

Categories