[security bulletin] HPESBGN03763 rev.1 - HPE SiteScope, Disclosure of Sensitive Information, Bypass Security Restriction, Remote Arbitrary Code Execution

DQotLS0tLUJFR0lOIFBHUCBTSUdORUQgTUVTU0FHRS0tLS0tDQpIYXNoOiBTSEEyNTYNCg0KTm90
ZTogdGhlIGN1cnJlbnQgdmVyc2lvbiBvZiB0aGUgZm9sbG93aW5nIGRvY3VtZW50IGlzIGF2YWls
YWJsZSBoZXJlOg0KaHR0cHM6Ly9oMjA1NjQud3d3Mi5ocGUuY29tL2hwc2MvZG9jL3B1YmxpYy9k
aXNwbGF5P2RvY0lkPWVtcl9uYS1ocGVzYmduMDM3NjNlbl91cw0KDQpTVVBQT1JUIENPTU1VTklD
QVRJT04gLSBTRUNVUklUWSBCVUxMRVRJTg0KDQpEb2N1bWVudCBJRDogaHBlc2JnbjAzNzYzZW5f
dXMNClZlcnNpb246IDENCg0KSFBFU0JHTjAzNzYzIHJldi4xIC0gSFBFIFNpdGVTY29wZSwgRGlz
Y2xvc3VyZSBvZiBTZW5zaXRpdmUgSW5mb3JtYXRpb24sIEJ5cGFzcyBTZWN1cml0eSBSZXN0cmlj
dGlvbiwgUmVtb3RlIEFyYml0cmFyeSBDb2RlIEV4ZWN1dGlvbg0KDQpOT1RJQ0U6IFRoZSBpbmZv
cm1hdGlvbiBpbiB0aGlzIFNlY3VyaXR5IEJ1bGxldGluIHNob3VsZCBiZSBhY3RlZCB1cG9uIGFz
IHNvb24gYXMgcG9zc2libGUuDQoNClJlbGVhc2UgRGF0ZTogMjAxNy0wNi0yNg0KTGFzdCBVcGRh
dGVkOiAyMDE3LTA2LTI2DQoNClBvdGVudGlhbCBTZWN1cml0eSBJbXBhY3Q6IExvY2FsOiBCeXBh
c3MgU2VjdXJpdHkgUmVzdHJpY3Rpb25zLCBEaXNjbG9zdXJlIG9mIFNlbnNpdGl2ZSBJbmZvcm1h
dGlvbjsgUmVtb3RlOiBBcmJpdHJhcnkgQ29kZSBFeGVjdXRpb24NCg0KU291cmNlOiBIZXdsZXR0
IFBhY2thcmQgRW50ZXJwcmlzZSwgUHJvZHVjdCBTZWN1cml0eSBSZXNwb25zZSBUZWFtDQoNClZV
TE5FUkFCSUxJVFkgU1VNTUFSWQ0KUG90ZW50aWFsIHNlY3VyaXR5IHZ1bG5lcmFiaWxpdGllcyBo
YXZlIGJlZW4gaWRlbnRpZmllZCBpbiBIUEUgU2l0ZVNjb3BlLiBUaGUgdnVsbmVyYWJpbGl0aWVz
IGNvdWxkIGJlIGV4cGxvaXRlZCB0byBhbGxvdyBkaXNjbG9zdXJlIG9mIHNlbnNpdGl2ZSBpbmZv
cm1hdGlvbiwgYnlwYXNzIHNlY3VyaXR5IHJlc3RyaWN0aW9uLCBhbmQgcmVtb3RlIGFyYml0cmFy
eSBjb2RlIGV4ZWN1dGlvbi4NCg0KUmVmZXJlbmNlczoNCg0KICAtIENWRS0yMDE3LTg5NTIgLSBB
dXRoZW50aWNhdGlvbiBpc3N1ZSwgUmVtb3RlIEFyYml0cmFyeSBDb2RlIEV4ZWN1dGlvbg0KICAt
IENWRS0yMDE3LTg5NDkgLSBDcnlwdG9ncmFwaGljIElzc3VlLCBMb2NhbCBEaXNjbG9zdXJlIG9m
IFNlbnNpdGl2ZSBJbmZvcm1hdGlvbg0KICAtIENWRS0yMDE3LTg5NTAgLSBDcnlwdG9ncmFwaGlj
IElzc3VlLCBMb2NhbCBEaXNjbG9zdXJlIG9mIFNlbnNpdGl2ZSBJbmZvcm1hdGlvbg0KICAtIENW
RS0yMDE3LTg5NTEgLSBMb2NhbCBCeXBhc3MgU2VjdXJpdHkgUmVzdHJpY3Rpb25zDQoNClNVUFBP
UlRFRCBTT0ZUV0FSRSBWRVJTSU9OUyo6IE9OTFkgaW1wYWN0ZWQgdmVyc2lvbnMgYXJlIGxpc3Rl
ZC4NCg0KICAtIEhQIFNpdGVTY29wZSBNb25pdG9ycyBTb2Z0d2FyZSBTZXJpZXMgLSB2MTEuMngs
IHYxMS4zeA0KDQpCQUNLR1JPVU5EDQoNCiAgQ1ZTUyBCYXNlIE1ldHJpY3MNCiAgPT09PT09PT09
PT09PT09PT0NCiAgUmVmZXJlbmNlLCBDVlNTIFYzIFNjb3JlL1ZlY3RvciwgQ1ZTUyBWMiBTY29y
ZS9WZWN0b3INCg0KICAgIENWRS0yMDE3LTg5NDkNCiAgICAgIDYuNyBDVlNTOjMuMC9BVjpML0FD
OkgvUFI6Ti9VSTpOL1M6VS9DOkgvSTpIL0E6Tg0KICAgICAgNS4wIChBVjpML0FDOk0vQXU6Uy9D
OkMvSTpQL0E6TikNCg0KICAgIENWRS0yMDE3LTg5NTANCiAgICAgIDYuNyBDVlNTOjMuMC9BVjpM
L0FDOkgvUFI6Ti9VSTpOL1M6VS9DOkgvSTpIL0E6Tg0KICAgICAgNS4wIChBVjpML0FDOk0vQXU6
Uy9DOkMvSTpQL0E6TikNCg0KICAgIENWRS0yMDE3LTg5NTENCiAgICAgIDcuNCBDVlNTOjMuMC9B
VjpML0FDOkgvUFI6Ti9VSTpOL1M6VS9DOkgvSTpIL0E6SA0KICAgICAgNS4wIChBVjpML0FDOk0v
QXU6Uy9DOkMvSTpQL0E6TikNCg0KICAgIENWRS0yMDE3LTg5NTINCiAgICAgIDguMSBDVlNTOjMu
MC9BVjpOL0FDOkgvUFI6Ti9VSTpOL1M6VS9DOkgvSTpIL0E6SA0KICAgICAgOS4zIChBVjpOL0FD
Ok0vQXU6Ti9DOkMvSTpDL0E6QykNCg0KICAgIEluZm9ybWF0aW9uIG9uIENWU1MgaXMgZG9jdW1l
bnRlZCBpbg0KICAgIEhQRSBDdXN0b21lciBOb3RpY2UgSFBTTi0yMDA4LTAwMiBoZXJlOg0KDQpo
dHRwczovL2gyMDU2NC53d3cyLmhwZS5jb20vaHBzYy9kb2MvcHVibGljL2Rpc3BsYXk/ZG9jSWQ9
ZW1yX25hLWMwMTM0NTQ5OQ0KDQpSRVNPTFVUSU9ODQoNCkhQRSBoYXMgcmVsZWFzZWQgZm9sbG93
aW5nIHNvZnR3YXJlIHVwZGF0ZXMgYW5kIG1pdGlnYXRpb24gaW5mb3JtYXRpb24gdG8gcmVzb2x2
ZSB0aGUgdnVsbmVyYWJpbGl0aWVzIGluIHRoZSBpbXBhY3RlZCB2ZXJzaW9ucyBvZiBIUEUgU2l0
ZVNjb3BlLg0KDQoqDQo8aHR0cHM6Ly9zb2Z0d2FyZXN1cHBvcnQuaHAuY29tL2dyb3VwL3NvZnR3
YXJlc3VwcG9ydC9zZWFyY2gtcmVzdWx0Ly0vZmFjZXRzZQ0KcmNoL2RvY3VtZW50L0tNMDI4MjEx
ODc+DQoNCioNCjxodHRwczovL3NvZnR3YXJlc3VwcG9ydC5ocC5jb20vZ3JvdXAvc29mdHdhcmVz
dXBwb3J0L3NlYXJjaC1yZXN1bHQvLS9mYWNldHNlDQpyY2gvZG9jdW1lbnQvS00wMjgyMTE4OD4N
Cg0KSElTVE9SWQ0KVmVyc2lvbjoxIChyZXYuMSkgLSAyNiBKdW5lIDIwMTcgSW5pdGlhbCByZWxl
YXNlDQoNClRoaXJkIFBhcnR5IFNlY3VyaXR5IFBhdGNoZXM6IFRoaXJkIHBhcnR5IHNlY3VyaXR5
IHBhdGNoZXMgdGhhdCBhcmUgdG8gYmUgaW5zdGFsbGVkIG9uIHN5c3RlbXMgcnVubmluZyBIZXds
ZXR0IFBhY2thcmQgRW50ZXJwcmlzZSAoSFBFKSBzb2Z0d2FyZSBwcm9kdWN0cyBzaG91bGQgYmUg
YXBwbGllZCBpbiBhY2NvcmRhbmNlIHdpdGggdGhlIGN1c3RvbWVyJ3MgcGF0Y2ggbWFuYWdlbWVu
dCBwb2xpY3kuDQoNClN1cHBvcnQ6IEZvciBpc3N1ZXMgYWJvdXQgaW1wbGVtZW50aW5nIHRoZSBy
ZWNvbW1lbmRhdGlvbnMgb2YgdGhpcyBTZWN1cml0eSBCdWxsZXRpbiwgY29udGFjdCBub3JtYWwg
SFBFIFNlcnZpY2VzIHN1cHBvcnQgY2hhbm5lbC4gRm9yIG90aGVyIGlzc3VlcyBhYm91dCB0aGUg
Y29udGVudCBvZiB0aGlzIFNlY3VyaXR5IEJ1bGxldGluLCBzZW5kIGUtbWFpbCB0byBzZWN1cml0
eS1hbGVydEBocGUuY29tLg0KDQpSZXBvcnQ6IFRvIHJlcG9ydCBhIHBvdGVudGlhbCBzZWN1cml0
eSB2dWxuZXJhYmlsaXR5IGZvciBhbnkgSFBFIHN1cHBvcnRlZA0KcHJvZHVjdDoNCiAgV2ViIGZv
cm06IGh0dHBzOi8vd3d3LmhwZS5jb20vaW5mby9yZXBvcnQtc2VjdXJpdHktdnVsbmVyYWJpbGl0
eQ0KICBFbWFpbDogc2VjdXJpdHktYWxlcnRAaHBlLmNvbQ0KDQpTdWJzY3JpYmU6IFRvIGluaXRp
YXRlIGEgc3Vic2NyaXB0aW9uIHRvIHJlY2VpdmUgZnV0dXJlIEhQRSBTZWN1cml0eSBCdWxsZXRp
biBhbGVydHMgdmlhIEVtYWlsOiBodHRwOi8vd3d3LmhwZS5jb20vc3VwcG9ydC9TdWJzY3JpYmVy
X0Nob2ljZQ0KDQpTZWN1cml0eSBCdWxsZXRpbiBBcmNoaXZlOiBBIGxpc3Qgb2YgcmVjZW50bHkg
cmVsZWFzZWQgU2VjdXJpdHkgQnVsbGV0aW5zIGlzIGF2YWlsYWJsZSBoZXJlOiBodHRwOi8vd3d3
LmhwZS5jb20vc3VwcG9ydC9TZWN1cml0eV9CdWxsZXRpbl9BcmNoaXZlDQoNClNvZnR3YXJlIFBy
b2R1Y3QgQ2F0ZWdvcnk6IFRoZSBTb2Z0d2FyZSBQcm9kdWN0IENhdGVnb3J5IGlzIHJlcHJlc2Vu
dGVkIGluIHRoZSB0aXRsZSBieSB0aGUgdHdvIGNoYXJhY3RlcnMgZm9sbG93aW5nIEhQU0IuDQoN
CjNDID0gM0NPTQ0KM1AgPSAzcmQgUGFydHkgU29mdHdhcmUNCkdOID0gSFBFIEdlbmVyYWwgU29m
dHdhcmUNCkhGID0gSFBFIEhhcmR3YXJlIGFuZCBGaXJtd2FyZQ0KTVUgPSBNdWx0aS1QbGF0Zm9y
bSBTb2Z0d2FyZQ0KTlMgPSBOb25TdG9wIFNlcnZlcnMNCk9WID0gT3BlblZNUw0KUFYgPSBQcm9D
dXJ2ZQ0KU1QgPSBTdG9yYWdlIFNvZnR3YXJlDQpVWCA9IEhQLVVYDQoNCkNvcHlyaWdodCAyMDE2
IEhld2xldHQgUGFja2FyZCBFbnRlcnByaXNlDQoNCkhld2xldHQgUGFja2FyZCBFbnRlcnByaXNl
IHNoYWxsIG5vdCBiZSBsaWFibGUgZm9yIHRlY2huaWNhbCBvciBlZGl0b3JpYWwgZXJyb3JzIG9y
IG9taXNzaW9ucyBjb250YWluZWQgaGVyZWluLiBUaGUgaW5mb3JtYXRpb24gcHJvdmlkZWQgaXMg
cHJvdmlkZWQgImFzIGlzIiB3aXRob3V0IHdhcnJhbnR5IG9mIGFueSBraW5kLiBUbyB0aGUgZXh0
ZW50IHBlcm1pdHRlZCBieSBsYXcsIG5laXRoZXIgSFAgb3IgaXRzIGFmZmlsaWF0ZXMsIHN1YmNv
bnRyYWN0b3JzIG9yIHN1cHBsaWVycyB3aWxsIGJlIGxpYWJsZSBmb3IgaW5jaWRlbnRhbCxzcGVj
aWFsIG9yIGNvbnNlcXVlbnRpYWwgZGFtYWdlcyBpbmNsdWRpbmcgZG93bnRpbWUgY29zdDsgbG9z
dCBwcm9maXRzOyBkYW1hZ2VzIHJlbGF0aW5nIHRvIHRoZSBwcm9jdXJlbWVudCBvZiBzdWJzdGl0
dXRlIHByb2R1Y3RzIG9yIHNlcnZpY2VzOyBvciBkYW1hZ2VzIGZvciBsb3NzIG9mIGRhdGEsIG9y
IHNvZnR3YXJlIHJlc3RvcmF0aW9uLiBUaGUgaW5mb3JtYXRpb24gaW4gdGhpcyBkb2N1bWVudCBp
cyBzdWJqZWN0IHRvIGNoYW5nZSB3aXRob3V0IG5vdGljZS4gSGV3bGV0dCBQYWNrYXJkIEVudGVy
cHJpc2UgYW5kIHRoZSBuYW1lcyBvZiBIZXdsZXR0IFBhY2thcmQgRW50ZXJwcmlzZSBwcm9kdWN0
cyByZWZlcmVuY2VkIGhlcmVpbiBhcmUgdHJhZGVtYXJrcyBvZiBIZXdsZXR0IFBhY2thcmQgRW50
ZXJwcmlzZSBpbiB0aGUgVW5pdGVkIFN0YXRlcyBhbmQgb3RoZXIgY291bnRyaWVzLiBPdGhlciBw
cm9kdWN0IGFuZCBjb21wYW55IG5hbWVzIG1lbnRpb25lZCBoZXJlaW4gbWF5IGJlIHRyYWRlbWFy
a3Mgb2YgdGhlaXIgcmVzcGVjdGl2ZSBvd25lcnMuDQotLS0tLUJFR0lOIFBHUCBTSUdOQVRVUkUt
LS0tLQ0KVmVyc2lvbjogR251UEcgdjENCg0KaVFFY0JBRUJDQUFHQlFKWlV0K3NBQW9KRUxYaEF4
dDdTWmFpU0xNSUFLakhldkRwdG9ENEpHS0NGazh5TktqcQ0KUW05MG5kb05vNWNmdHBGeE5qazli
Wkc3dzl4d2UzSmNiRzEzYnVheG1PRDI5Y1hWaFhuem5NNCtxRm4zejhDTw0KRUNaSGJlZjB5UkQw
ZTFJY3BTNEUwT2JpaGpXamhkTGMraWQwQTlVY1hNTmRab0pxc1VqRWhhRHpxT2RROTFqRw0KUEFN
a2lIakgyRVVXZUVsaW13cnpNV0ZWSVVwNHJRWVJ4U0hJZEZZY0FKd3EwWDV0ams4L2EwOWVKZ1VE
T0RvMQ0KOTcwbllRdE1LVm04KzRUSmNjcG0yaHpvVkhWbU1TSXh4OEtqWXV1VEhoZFM4VVVqbito
V3NtUHM0cktsWHdlag0KNUlKZTRackR4V3o2M3JmRmNLWVQ5dTR3czdvNmQwbnN0dHBYOWxmOW52
OFV3cEQzVnBLSDVkU2I0WVZoOVQwPQ0KPWgzQlENCi0tLS0tRU5EIFBHUCBTSUdOQVRVUkUtLS0t
LQ0K