This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Hp First view 2011-07-01
Product Operations Agent Last view 2014-10-18
Version 8.60.006 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:hp:operations_agent

Activity : Overall

Related : CVE

  Date Alert Description
4.3 2014-10-18 CVE-2014-2647

Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

10 2012-07-11 CVE-2012-2020

Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1326.

10 2012-07-11 CVE-2012-2019

Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325.

6.4 2011-07-01 CVE-2011-2608

ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.

CWE : Common Weakness Enumeration

%idName
50% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
50% (1) CWE-20 Improper Input Validation

SAINT Exploits

Description Link
HP Operations Agent Opcode 0x8c vulnerability More info here
HP Operations Agent Opcode 0x34 vulnerability More info here

Open Source Vulnerability Database (OSVDB)

id Description
73502 HP Operations Manager OV Communication Broker (ovbbccb.exe) Register Request ...

ExploitDB Exploits

id Description
35076 HP Operations Agent Remote XSS iFrame Injection

Information Assurance Vulnerability Management (IAVM)

id Description
2014-B-0139 Hewlett Packard Operations Manager/Agent Cross Site Scripting Vulnerability
Severity: Category I - VMSKEY: V0055683
2011-B-0091 HP Operations Manager Arbitrary File Deletion Vulnerability
Severity: Category I - VMSKEY: V0029567

Snort® IPS/IDS

Date Description
2019-05-30 HP OpenView Operations Agent request attempt
RuleID : 49947 - Type : POLICY-OTHER - Revision : 2
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24836 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24835 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24834 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24833 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24832 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24831 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24830 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24829 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24828 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24827 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24320 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24319 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24318 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24317 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24316 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24315 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24314 - Type : SERVER-WEBAPP - Revision : 6
2014-01-10 HP OpenView Operations Agent request attempt
RuleID : 24313 - Type : SERVER-WEBAPP - Revision : 14
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 23961 - Type : SERVER-WEBAPP - Revision : 10
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 23960 - Type : SERVER-WEBAPP - Revision : 10
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 23959 - Type : SERVER-WEBAPP - Revision : 10
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 23958 - Type : SERVER-WEBAPP - Revision : 10

Nessus® Vulnerability Scanner

id Description
2014-10-22 Name: The remote web server is affected by a cross-site scripting vulnerability.
File: hp_operations_agent_CVE-2014-2647.nasl - Type: ACT_GATHER_INFO
2013-09-27 Name: The remote web server has an arbitrary file deletion vulnerability.
File: hp_openview_bbc_file_deletion.nasl - Type: ACT_GATHER_INFO