Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-22435

CVE-2024-22435: ViewPoint Enterprise Info Disclosure Flaw

CVE-2024-22435 is an information disclosure vulnerability in Web ViewPoint Enterprise software that allows unauthorized access to NonStop system resources. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-22435 Overview

CVE-2024-22435 is an information disclosure vulnerability in HPE Web ViewPoint Enterprise software running on NonStop systems. The flaw allows unauthorized users to access resources they should not be permitted to view. The vulnerability maps to [CWE-200], indicating exposure of sensitive information to an unauthorized actor.

HPE published a security bulletin describing the issue and providing remediation guidance. The vulnerability is exploitable over the network but requires user interaction and high attack complexity, which limits opportunistic exploitation while still posing meaningful risk to confidentiality, integrity, and availability across security scopes.

Critical Impact

Successful exploitation grants unauthorized access to resources on HPE NonStop systems running Web ViewPoint Enterprise, potentially exposing sensitive operational and business data.

Affected Products

  • HPE Web ViewPoint Enterprise software
  • HPE NonStop systems running Web ViewPoint Enterprise
  • Refer to the HPE Security Bulletin for specific affected versions

Discovery Timeline

  • 2024-04-15 - CVE-2024-22435 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2024-22435

Vulnerability Analysis

The vulnerability resides in HPE Web ViewPoint Enterprise, a management and monitoring tool for HPE NonStop platforms. Web ViewPoint Enterprise exposes browser-based interfaces that administrators use to observe system health, processes, and operational data on mission-critical NonStop deployments.

The weakness is classified under [CWE-200], Exposure of Sensitive Information to an Unauthorized Actor. An attacker who successfully exploits the issue can reach resources on the NonStop system that should be restricted. The scope change in the impact metrics indicates the flaw can affect components beyond the immediate vulnerable code, expanding the potential blast radius across the managed environment.

Exploitation requires user interaction and presents high attack complexity, suggesting the attacker must lure a privileged user into a specific action or chain multiple conditions to succeed. Despite those prerequisites, all three security properties — confidentiality, integrity, and availability — are rated as high impact in the advisory.

Root Cause

HPE has not publicly disclosed the precise code defect. The CWE-200 mapping indicates the root cause is improper restriction of access to sensitive resources rather than memory corruption or injection. Authorization or access control logic in Web ViewPoint Enterprise fails to consistently enforce restrictions on certain resources reachable through the web interface.

Attack Vector

The attack vector is network-based. A remote attacker interacts with the Web ViewPoint Enterprise application over the network and requires a user to take an action that triggers the vulnerable code path. Once the conditions are met, the attacker accesses NonStop system resources outside their authorized scope. Refer to the HPE Security Bulletin for additional technical detail.

Detection Methods for CVE-2024-22435

Indicators of Compromise

  • Unexpected HTTP/HTTPS requests to Web ViewPoint Enterprise endpoints from non-administrative source addresses.
  • Access to NonStop resources by accounts that historically have not interacted with Web ViewPoint Enterprise.
  • Anomalous session activity, including sessions initiated outside normal administrative windows.

Detection Strategies

  • Audit Web ViewPoint Enterprise access logs for requests targeting resources not associated with the requesting user's role.
  • Correlate web interface authentication events with subsequent NonStop resource access to identify privilege boundary violations.
  • Baseline normal administrator behavior and alert on deviations such as unusual resource enumeration patterns.

Monitoring Recommendations

  • Forward Web ViewPoint Enterprise and NonStop audit logs to a centralized SIEM for retention and correlation.
  • Monitor outbound traffic from NonStop management hosts for signs of exfiltration following suspicious access events.
  • Track configuration changes and resource access on NonStop systems and alert on out-of-policy modifications.

How to Mitigate CVE-2024-22435

Immediate Actions Required

  • Apply the patch referenced in the HPE Security Bulletin for Web ViewPoint Enterprise.
  • Inventory all NonStop systems running Web ViewPoint Enterprise and verify their patch level against the HPE advisory.
  • Restrict network access to the Web ViewPoint Enterprise management interface to known administrator networks.

Patch Information

HPE has released updated Web ViewPoint Enterprise software addressing CVE-2024-22435. Administrators should consult the official HPE Security Bulletin for the fixed versions and upgrade instructions applicable to their NonStop environment.

Workarounds

  • Place Web ViewPoint Enterprise behind a VPN or jump host to limit network reachability.
  • Enforce strict role-based access control and remove unused administrator accounts from the management interface.
  • Require multi-factor authentication for any account permitted to access Web ViewPoint Enterprise.
  • Educate administrators about phishing and social engineering, since exploitation requires user interaction.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.