Executive Summary
Summary | |
---|---|
Title | HP OpenView Operations (OVO) Agents Running Shared Trace Service, Remote Arbitrary Code Execution |
Informations | |||
---|---|---|---|
Name | HPSBMA02239 SSRT061260 | First vendor Publication | 2007-08-07 |
Vendor | HP | Last vendor Modification | 2008-01-08 |
Severity (Vendor) | N/A | Revision | 3 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A potential security vulnerability has been identified in HP OpenView Operations (OVO) Agents running Shared Trace Service. The vulnerability could be remotely exploited to execute arbitrary code. |
Original Source
Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01110576 |
SAINT Exploits
Description | Link |
---|---|
HP OpenView Operations OVTrace buffer overflow | More info here |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
39527 | HP OpenView Operations Shared Trace Service (OVTrace) Remote Overflows Multiple buffer overflows exist in OpenView Operations. OVTrace fails to validate data passed to multiple functions resulting in stack overflows. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2007-08-22 | IAVM : 2007-T-0033 - Hewlett-Packard Openview Multiple Remote Buffer Overflow Vulnerabilities Severity : Category I - VMSKEY : V0014842 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | HP OpenView OVTrace buffer overflow attempt RuleID : 12666 - Revision : 9 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-01-15 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_37335.nasl - Type : ACT_GATHER_INFO |
2008-01-15 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_37336.nasl - Type : ACT_GATHER_INFO |
2008-01-15 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_37397.nasl - Type : ACT_GATHER_INFO |
2008-01-15 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_37398.nasl - Type : ACT_GATHER_INFO |
2008-01-15 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_37399.nasl - Type : ACT_GATHER_INFO |
2007-12-04 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_37141.nasl - Type : ACT_GATHER_INFO |
2007-11-20 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35457.nasl - Type : ACT_GATHER_INFO |
2007-10-03 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_36773.nasl - Type : ACT_GATHER_INFO |
2007-10-03 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_36901.nasl - Type : ACT_GATHER_INFO |
2007-10-03 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_36902.nasl - Type : ACT_GATHER_INFO |
2007-09-25 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_36278.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:38:11 |
|