Executive Summary
Summary | |
---|---|
Title | HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code, Unauthorized Access to Data |
Informations | |||
---|---|---|---|
Name | HPSBMA02406 SSRT080100 | First vendor Publication | 2009-02-04 |
Vendor | HP | Last vendor Modification | 2009-02-17 |
Severity (Vendor) | N/A | Revision | 2 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). The vulnerabilities could be exploited remotely to allow execution of arbitrary code or unauthorized access to data. |
Original Source
Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01661610 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
33 % | CWE-200 | Information Exposure |
33 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
33 % | CWE-20 | Improper Input Validation |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
53240 | HP OpenView Network Node Manager (OV NNM) ovlaunch CGI Host Header Remote Ove... |
53238 | HP OpenView Network Node Manager (OV NNM) webappmon.exe Arbitrary Code Execution |
53237 | HP OpenView Network Node Manager (OV NNM) nnmRptConfig.exe Log Directory Path... |
53236 | HP OpenView Network Node Manager (OV NNM) ovlaunch.exe Configuration Informat... |
53235 | HP OpenView Network Node Manager (OV NNM) OpenView5.exe Arbitrary Code Execution |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | HP OpenView Network Node Manager ovlaunch host field overflow attempt RuleID : 16204 - Revision : 8 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-06-15 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_38782.nasl - Type : ACT_GATHER_INFO |
2009-06-15 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_38783.nasl - Type : ACT_GATHER_INFO |
2009-02-12 | Name : The remote web server contains a CGI script that is affected by an informatio... File : openview_nnm_ovdebug_disclosure.nasl - Type : ACT_ATTACK |
2009-02-12 | Name : The remote web server contains a CGI script that is affected by a command inj... File : openview_nnm_sel_cmd_injection.nasl - Type : ACT_ATTACK |
2008-11-25 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_38761.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:38:14 |
|