Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title HP ProLiant Essentials Rapid Deployment Pack (RDP) Running Symantec Altiris Deployment Solution, Remote SQL Injection, Remote or Local Gain Extended Privileges, Local Denial of Service (DoS)
Informations
Name HPSBMA02369 SSRT080115 First vendor Publication 2008-09-17
Vendor HP Last vendor Modification 2008-09-17
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Potential vulnerabilities have been identified with HP ProLiant Essentials Rapid Deployment Pack (RDP) running Symantec Altiris Deployment Solution. The vulnerabilities could be exploited remotely to perform SQL injection or to gain extended privileges. The vulnerabilities could be exploited locally to gain extended privileges or to cause a Denial of Service (DoS).

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01548422

CWE : Common Weakness Enumeration

% Id Name
67 % CWE-264 Permissions, Privileges, and Access Controls
17 % CWE-255 Credentials Management
17 % CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 23

SAINT Exploits

Description Link
Symantec Altiris DS SQL injection More info here

Open Source Vulnerability Database (OSVDB)

Id Description
45318 Symantec Altiris Deployment Solution Installation Directory Permission Weakne...

45317 Symantec Altiris Deployment Solution Registry Keys Permission Weakness

45316 Symantec Altiris Deployment Solution tooltip Privilege Escalation

45315 Symantec Altiris Deployment Solution Authenticated Privileged Command Prompt ...

45314 Symantec Altiris Deployment Solution Weakly Encrypted Domain Credential Remot...

45313 Symantec Altiris Deployment Solution Client Come-alive Packet Multiple Field ...

Nessus® Vulnerability Scanner

Date Description
2008-05-15 Name : The remote Windows host has a program that is affected by multiple vulnerabil...
File : altiris_aclient_6_9_176.nasl - Type : ACT_GATHER_INFO
2008-05-15 Name : The remote Windows host has a program that is affected by multiple vulnerabil...
File : altiris_deployment_server_6_9_176.nasl - Type : ACT_GATHER_INFO