Executive Summary

Summary
Title HP Insight Management Agents Running on Linux and Windows, Remote Full Path Disclosure
Informations
Name HPSBMA02616 SSRT100231 First vendor Publication 2010-12-14
Vendor HP Last vendor Modification 2010-12-14
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A potential security vulnerability has been identified with HP Insight Management Agents running on Linux and Windows. The vulnerability could be exploited remotely resulting in full path disclosure.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02653973

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-200 Information Exposure

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 30

Open Source Vulnerability Database (OSVDB)

Id Description
69977 HP Insight Management Agents hmanics/hmanics.snmp.php Path Disclosure

HP Insight Management Agents contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker uses an unspecified request to the hmanics/hmanics.snmp.php script which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.