Skip to main content

HPE Releases Security Update

Report a cyber attack: call 0300 303 5222 or email [email protected]

Affected platforms

The following platforms are known to be affected:

HPE Systems Insight Manager Versions: 7.6


Threat details

Introduction

Hewlett Packard Enterprise (HPE) has released updates to address a remote code execution vulnerability in their Systems Insight Manager. They claim that a remote unauthenticated attacker could exploit this to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review HPE security bulletin HPESBGN04068 and apply the following workarounds in lieu of an official update:

  1. Stop the HPE SIM Service
  2. Delete C:\Program Files\HP\Systems Insight Manager\jboss\server\hpsim\deploy\simsearch.war from SIM installed path del /Q /F C:\Program Files\HP\Systems Insight Manager\jboss\server\hpsim\deploy\simsearch.war
  3. Restart the HPE SIM Service
  4. Wait for HPE SIM web page https://SIM_IP:50000 to be accessible and execute the following command from command prompt: mxtool -r -f tools\multi-cms-search.xml 1>nul 2>nul

Last edited: 16 December 2021 10:49 am