HP Version Control Repository Manager (VCRM) Heartbeat Information Disclosure (Heartbleed)
High Nessus Plugin ID 77025
SynopsisThe remote host contains software that is affected by an information disclosure vulnerability.
DescriptionThe HP Version Control Repository Manager (VCRM) install on the remote Windows host is version 7.2.0, 7.2.1, 7.2.2, 7.3.0, or 7.3.1. It is, therefore, affected by an information disclosure vulnerability.
An out-of-bounds read error, known as the 'Heartbleed Bug', exists related to handling TLS heartbeat extensions that could allow an attacker to obtain sensitive information such as primary key material, secondary key material, and other protected content.
SolutionUpgrade to VCRM 7.3.2 or later.