This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Hp First view 2010-02-09
Product Operations Agent Last view 2017-05-04
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:hp:operations_agent:11.0:*:*:*:*:*:*:* 6
cpe:2.3:a:hp:operations_agent:8.53:*:*:*:*:*:*:* 5
cpe:2.3:a:hp:operations_agent:7.36:*:*:*:*:*:*:* 5
cpe:2.3:a:hp:operations_agent:8.60:*:*:*:*:*:*:* 5
cpe:2.3:a:hp:operations_agent:8.60.008:*:*:*:*:*:*:* 4
cpe:2.3:a:hp:operations_agent:8.60.501:*:*:*:*:*:*:* 4
cpe:2.3:a:hp:operations_agent:8.60.005:*:*:*:*:*:*:* 4
cpe:2.3:a:hp:operations_agent:8.60.007:*:*:*:*:*:*:* 4
cpe:2.3:a:hp:operations_agent:8.60.006:*:*:*:*:*:*:* 4
cpe:2.3:a:hp:operations_agent:8.51:*:*:*:*:*:*:* 4
cpe:2.3:a:hp:operations_agent:8.52:*:*:*:*:*:*:* 4
cpe:2.3:a:hp:operations_agent:8.51.102:*:*:*:*:*:*:* 3
cpe:2.3:a:hp:operations_agent:8.60.7:*:*:*:*:*:*:* 3
cpe:2.3:a:hp:operations_agent:11.13:*:*:*:*:*:*:* 1
cpe:2.3:a:hp:operations_agent:11.15:*:*:*:*:*:*:* 1
cpe:2.3:a:hp:operations_agent:11.14:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
7.5 2017-05-04 CVE-2017-3733

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

4.3 2014-10-18 CVE-2014-2647

Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.4 2014-08-12 CVE-2014-2630

Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.

10 2012-07-11 CVE-2012-2020

Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1326.

10 2012-07-11 CVE-2012-2019

Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325.

3.2 2011-11-23 CVE-2011-4160

Unspecified vulnerability in HP Operations Agent 11.00 and Performance Agent 4.73 and 5.0 on AIX, HP-UX, Linux, and Solaris allows local users to bypass intended directory-access restrictions via unknown vectors.

6.4 2011-07-01 CVE-2011-2608

ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.

6.8 2010-09-08 CVE-2010-3005

Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows local users to gain privileges via unknown vectors.

7.5 2010-09-08 CVE-2010-3004

Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.

10 2010-02-09 CVE-2010-0444

HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute arbitrary code via unspecified vectors.

CWE : Common Weakness Enumeration

%idName
50% (2) CWE-20 Improper Input Validation
25% (1) CWE-255 Credentials Management
25% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

SAINT Exploits

Description Link
HP Operations Agent Opcode 0x8c vulnerability More info here
HP Operations Agent Opcode 0x34 vulnerability More info here

Open Source Vulnerability Database (OSVDB)

id Description
77296 HP Operations / Performance Agent Local Unspecified Directory Access Restrict...
73502 HP Operations Manager OV Communication Broker (ovbbccb.exe) Register Request ...
67795 HP Operations Agent on Windows Unspecified Remote Code Execution
67794 HP Operations Agent on Windows Unspecified Local Privilege Escalation
62213 HP Operations Agent opc_op User Account Null Password Authentication Bypass

ExploitDB Exploits

id Description
35076 HP Operations Agent Remote XSS iFrame Injection

Information Assurance Vulnerability Management (IAVM)

id Description
2014-B-0139 Hewlett Packard Operations Manager/Agent Cross Site Scripting Vulnerability
Severity: Category I - VMSKEY: V0055683
2011-B-0091 HP Operations Manager Arbitrary File Deletion Vulnerability
Severity: Category I - VMSKEY: V0029567

Snort® IPS/IDS

Date Description
2019-05-30 HP OpenView Operations Agent request attempt
RuleID : 49947 - Type : POLICY-OTHER - Revision : 2
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24836 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24835 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24834 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24833 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24832 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24831 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24830 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24829 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24828 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24827 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24320 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24319 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24318 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24317 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24316 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24315 - Type : SERVER-WEBAPP - Revision : 9
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 24314 - Type : SERVER-WEBAPP - Revision : 6
2014-01-10 HP OpenView Operations Agent request attempt
RuleID : 24313 - Type : SERVER-WEBAPP - Revision : 14
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 23961 - Type : SERVER-WEBAPP - Revision : 10
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 23960 - Type : SERVER-WEBAPP - Revision : 10
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 23959 - Type : SERVER-WEBAPP - Revision : 10
2014-01-10 HP OpenView Operations Agent buffer overflow attempt
RuleID : 23958 - Type : SERVER-WEBAPP - Revision : 10

Nessus® Vulnerability Scanner

id Description
2017-10-18 Name: An application installed on the remote host is affected by multiple vulnerabi...
File: virtualbox_5_1_30.nasl - Type: ACT_GATHER_INFO
2017-02-23 Name: A service running on the remote host is affected by a denial of service vulne...
File: openssl_1_1_0e.nasl - Type: ACT_GATHER_INFO
2017-02-17 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_1a802ba9f44411e69940b499baebfeaf.nasl - Type: ACT_GATHER_INFO
2014-10-22 Name: The remote web server is affected by a cross-site scripting vulnerability.
File: hp_operations_agent_CVE-2014-2647.nasl - Type: ACT_GATHER_INFO
2013-09-27 Name: The remote web server has an arbitrary file deletion vulnerability.
File: hp_openview_bbc_file_deletion.nasl - Type: ACT_GATHER_INFO