CVE-2018-7107: HPE Device Entitlement Gateway
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege.
Affected products
- HPE Device Entitlement Gateway: version 3.2.4 only; version 3.3 only; version 3.3.1 only
Published 2018-09-27. Last modified 2026-06-17.