Summary
Detail | |||
---|---|---|---|
Vendor | Hp | First view | 2011-07-01 |
Product | Operations Agent | Last view | 2014-10-18 |
Version | 8.60.006 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:hp:operations_agent |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4.3 | 2014-10-18 | CVE-2014-2647 | Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
10 | 2012-07-11 | CVE-2012-2020 | Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1326. |
10 | 2012-07-11 | CVE-2012-2019 | Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325. |
6.4 | 2011-07-01 | CVE-2011-2608 | ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
50% (1) | CWE-20 | Improper Input Validation |
SAINT Exploits
Description | Link |
---|---|
HP Operations Agent Opcode 0x8c vulnerability | More info here |
HP Operations Agent Opcode 0x34 vulnerability | More info here |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
73502 | HP Operations Manager OV Communication Broker (ovbbccb.exe) Register Request ... |
ExploitDB Exploits
id | Description |
---|---|
35076 | HP Operations Agent Remote XSS iFrame Injection |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2014-B-0139 | Hewlett Packard Operations Manager/Agent Cross Site Scripting Vulnerability Severity: Category I - VMSKEY: V0055683 |
2011-B-0091 | HP Operations Manager Arbitrary File Deletion Vulnerability Severity: Category I - VMSKEY: V0029567 |
Snort® IPS/IDS
Date | Description |
---|---|
2019-05-30 | HP OpenView Operations Agent request attempt RuleID : 49947 - Type : POLICY-OTHER - Revision : 2 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24836 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24835 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24834 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24833 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24832 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24831 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24830 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24829 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24828 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24827 - Type : SERVER-WEBAPP - Revision : 7 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24320 - Type : SERVER-WEBAPP - Revision : 9 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24319 - Type : SERVER-WEBAPP - Revision : 9 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24318 - Type : SERVER-WEBAPP - Revision : 9 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24317 - Type : SERVER-WEBAPP - Revision : 9 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24316 - Type : SERVER-WEBAPP - Revision : 9 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24315 - Type : SERVER-WEBAPP - Revision : 9 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 24314 - Type : SERVER-WEBAPP - Revision : 6 |
2014-01-10 | HP OpenView Operations Agent request attempt RuleID : 24313 - Type : SERVER-WEBAPP - Revision : 14 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 23961 - Type : SERVER-WEBAPP - Revision : 10 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 23960 - Type : SERVER-WEBAPP - Revision : 10 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 23959 - Type : SERVER-WEBAPP - Revision : 10 |
2014-01-10 | HP OpenView Operations Agent buffer overflow attempt RuleID : 23958 - Type : SERVER-WEBAPP - Revision : 10 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2014-10-22 | Name: The remote web server is affected by a cross-site scripting vulnerability. File: hp_operations_agent_CVE-2014-2647.nasl - Type: ACT_GATHER_INFO |
2013-09-27 | Name: The remote web server has an arbitrary file deletion vulnerability. File: hp_openview_bbc_file_deletion.nasl - Type: ACT_GATHER_INFO |