CVE-2012-2012

critical
Published 2012-06-29 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: hp-security-alert@hp.com — http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041

OS impact

OSVersionStatusFixed in
linux linux-kernelnot-affected

Application impact

VendorProductVersionsFixed
hpsystem_management_homepage{"endIncluding":"7.1.0-16"}
hpsystem_management_homepage2.0.0
hpsystem_management_homepage2.0.1
hpsystem_management_homepage2.0.1.104
hpsystem_management_homepage2.0.2
hpsystem_management_homepage2.0.2.106
hpsystem_management_homepage2.1
hpsystem_management_homepage2.1.0-103
hpsystem_management_homepage2.1.0-103\(a\)
hpsystem_management_homepage2.1.0-109
hpsystem_management_homepage2.1.0-118
hpsystem_management_homepage2.1.0.121
hpsystem_management_homepage2.1.1
hpsystem_management_homepage2.1.2
hpsystem_management_homepage2.1.2-127
hpsystem_management_homepage2.1.2.127
hpsystem_management_homepage2.1.3
hpsystem_management_homepage2.1.3.132
hpsystem_management_homepage2.1.4
hpsystem_management_homepage2.1.4-143
hpsystem_management_homepage2.1.4.143
hpsystem_management_homepage2.1.5
hpsystem_management_homepage2.1.5-146
hpsystem_management_homepage2.1.5.146
hpsystem_management_homepage2.1.6
hpsystem_management_homepage2.1.6-156
hpsystem_management_homepage2.1.6.156
hpsystem_management_homepage2.1.7
hpsystem_management_homepage2.1.7-168
hpsystem_management_homepage2.1.7.168
hpsystem_management_homepage2.1.8
hpsystem_management_homepage2.1.8-177
hpsystem_management_homepage2.1.8.179
hpsystem_management_homepage2.1.9
hpsystem_management_homepage2.1.9-178
hpsystem_management_homepage2.1.10
hpsystem_management_homepage2.1.10-186
hpsystem_management_homepage2.1.10.186
hpsystem_management_homepage2.1.11
hpsystem_management_homepage2.1.11-197
hpsystem_management_homepage2.1.11.197
hpsystem_management_homepage2.1.12-118
hpsystem_management_homepage2.1.12-200
hpsystem_management_homepage2.1.12.201
hpsystem_management_homepage2.1.14
hpsystem_management_homepage2.1.14.20
hpsystem_management_homepage2.1.15
hpsystem_management_homepage2.1.15-210
hpsystem_management_homepage2.1.15.210
hpsystem_management_homepage2.2.6
hpsystem_management_homepage2.2.8
hpsystem_management_homepage3.0.0
hpsystem_management_homepage3.0.0-68
hpsystem_management_homepage3.0.0.64
hpsystem_management_homepage3.0.1
hpsystem_management_homepage3.0.1-73
hpsystem_management_homepage3.0.1.73
hpsystem_management_homepage3.0.2
hpsystem_management_homepage3.0.2-77
hpsystem_management_homepage3.0.2.77
hpsystem_management_homepage6.0
hpsystem_management_homepage6.0.0-95
hpsystem_management_homepage6.0.0.96
hpsystem_management_homepage6.1
hpsystem_management_homepage6.1.0-103
hpsystem_management_homepage6.1.0.102
hpsystem_management_homepage6.2.0
hpsystem_management_homepage6.2.2.7
hpsystem_management_homepage6.3.0
hpsystem_management_homepage6.3.1
hpsystem_management_homepage7.0

References

Verify integrity in audit chain (admin only). AS-IS.