Executive Summary
Summary | |
---|---|
Title | HP ProLiant Essentials Rapid Deployment Pack (RDP) Running Symantec Altiris Deployment Solution, Remote SQL Injection, Remote or Local Gain Extended Privileges, Local Denial of Service (DoS) |
Informations | |||
---|---|---|---|
Name | HPSBMA02369 SSRT080115 | First vendor Publication | 2008-09-17 |
Vendor | HP | Last vendor Modification | 2008-09-17 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Potential vulnerabilities have been identified with HP ProLiant Essentials Rapid Deployment Pack (RDP) running Symantec Altiris Deployment Solution. The vulnerabilities could be exploited remotely to perform SQL injection or to gain extended privileges. The vulnerabilities could be exploited locally to gain extended privileges or to cause a Denial of Service (DoS). |
Original Source
Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01548422 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
67 % | CWE-264 | Permissions, Privileges, and Access Controls |
17 % | CWE-255 | Credentials Management |
17 % | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
Symantec Altiris DS SQL injection | More info here |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
45318 | Symantec Altiris Deployment Solution Installation Directory Permission Weakne... |
45317 | Symantec Altiris Deployment Solution Registry Keys Permission Weakness |
45316 | Symantec Altiris Deployment Solution tooltip Privilege Escalation |
45315 | Symantec Altiris Deployment Solution Authenticated Privileged Command Prompt ... |
45314 | Symantec Altiris Deployment Solution Weakly Encrypted Domain Credential Remot... |
45313 | Symantec Altiris Deployment Solution Client Come-alive Packet Multiple Field ... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-05-15 | Name : The remote Windows host has a program that is affected by multiple vulnerabil... File : altiris_aclient_6_9_176.nasl - Type : ACT_GATHER_INFO |
2008-05-15 | Name : The remote Windows host has a program that is affected by multiple vulnerabil... File : altiris_deployment_server_6_9_176.nasl - Type : ACT_GATHER_INFO |