LiveActive security incident?Get immediate response
CVE Record

CVE-2017-8985: HPE XP Storage using Hitachi Global Link Manager (HGLM) has a local authenticated information disclosure vu...

HPE XP Storage using Hitachi Global Link Manager (HGLM) has a local authenticated information disclosure vulnerability in HGLM version HGLM 6.3.0-00 to 8.5.2-00.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This vulnerability may let a local authenticated user disclose information from HPE XP Storage environments using Hitachi Global Link Manager. The public record names affected HGLM versions but does not describe the exposed information or business impact. It matters mainly where HGLM is present and local access is not tightly controlled.

Executive priority

Make this an asset-driven remediation task. It is not justified as an emergency from the provided evidence, but affected storage management systems should be checked because information disclosure on infrastructure tooling can aid broader compromise.

Technical view

CVE-2017-8985 is a local authenticated information disclosure issue affecting HPE XP Storage using HGLM versions 6.3.0-00 through 8.5.2-00. The source bundle provides no CVSS score, CWE, exploit details, or affected data type beyond the vulnerability class and version range.

Likely exposure

Exposure is limited to organizations running HPE XP Storage with HGLM 6.3.0-00 to 8.5.2-00. The described attacker already needs local authenticated access.

Exploitation context

The CVE is not listed as KEV in the provided bundle. No cited source claims active exploitation, public exploit availability, or remote exploitation. Evidence only supports a local authenticated information disclosure scenario.

Researcher notes

Key unknowns are the disclosed data, exact vulnerable component, privilege level after local authentication, and vendor fix details. Avoid assuming exploitability beyond local authenticated access unless the HPE advisory or later evidence confirms it.

Mitigation direction

  • Check HPE advisory hpesbhf03819en_us for current remediation guidance.
  • Upgrade or apply the HPE-recommended fix if the installed HGLM version is affected.
  • Restrict local access to HGLM management hosts to trusted administrators.
  • Review local account hygiene on systems hosting HGLM.
  • Treat compensating controls as temporary until vendor guidance is applied.

Validation and detection

  • Inventory HGLM installations supporting HPE XP Storage.
  • Confirm whether installed versions fall between 6.3.0-00 and 8.5.2-00.
  • Verify who has local authenticated access to HGLM hosts.
  • Confirm remediation status against the HPE advisory.
  • Document any unsupported or unpatched affected installations.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-8985 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Hewlett Packard EnterpriseXP Storage using HGLM6.3.0-00 to 8.5.2-00Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.