Executive Summary

Summary
Title HP OpenView Performance Insight Server, Remote Execution of Arbitrary Code
Informations
Name HPSBMA02627 SSRT090246 First vendor Publication 2011-01-31
Vendor HP Last vendor Modification 2011-06-14
Severity (Vendor) N/A Revision 2

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A potential vulnerability has been identified with HP OpenView Performance Insight Server. The vulnerability could be exploited remotely to execute arbitrary code.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02695453

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 5

SAINT Exploits

Description Link
HP OpenView Performance Insight Server Backdoor Account More info here

OpenVAS Exploits

Date Description
2011-02-03 Name : HP OpenView Performance Insight Server 'doPost()' Remote Arbitrary Code Execu...
File : nvt/gb_hp_performance_insight_46079.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
70754 HP OpenView Performance Insight com.trinagy.security.XMLUserManager Default A...

HP OpenView Performance Insight contains a flaw related to a hidden account within the 'com.trinagy.security.XMLUserManager' Java class. This may allow a remote attacker access to the 'com.trinagy.servlet.HelpManagerServlet' class, where they gain acess to the 'doPost()' method, which they may use to upload arbitrary files and execute arbitrary code.

Snort® IPS/IDS

Date Description
2014-01-10 HP OpenView Performance Insight Server backdoor account code execution attempt
RuleID : 18560 - Revision : 8 - Type : SERVER-WEBAPP
2014-01-10 HP OpenView Performance Insight Server backdoor account code execution attempt
RuleID : 18559 - Revision : 9 - Type : SERVER-WEBAPP

Nessus® Vulnerability Scanner

Date Description
2011-02-02 Name : It is possible to log on the remote web application by using a hidden account.
File : hp_openview_perf_insight_backdoor.nasl - Type : ACT_ATTACK