Vulnerability CVE-2010-0447


Published: 2010-03-10   Modified: 2012-02-13

Description:
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.

See advisories in our WLB2 database:
Topic
Author
Date
High
HP openview Performance Insight 5.4 Remote Execution of ArbitraryCommands
HP
15.03.2010

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
HP -> Openview performance insight 

 References:
http://marc.info/?l=bugtraq&m=126815897824020&w=2
http://www.securityfocus.com/archive/1/509984/100/0/threaded
http://www.securityfocus.com/bid/38611
http://www.vupen.com/english/advisories/2010/0555
http://www.zerodayinitiative.com/advisories/ZDI-10-026
https://exchange.xforce.ibmcloud.com/vulnerabilities/56757

Copyright 2024, cxsecurity.com

 

Back to Top