Executive Summary

Summary
Title HP-UX Running Role-Based Access Control (RBAC), Local Unauthorized Access
Informations
Name HPSBUX02457 SSRT090174 First vendor Publication 2009-09-21
Vendor HP Last vendor Modification 2009-09-21
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 7.2 Attack Range Local
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A potential security vulnerability has been identified with HP-UX running Role-Based Access Control (RBAC). The vulnerability could be exploited locally to gain unauthorized access.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01866178

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:6328
 
Oval ID: oval:org.mitre.oval:def:6328
Title: HP-UX Running Role-Based Access Control (RBAC), Local Unauthorized Access
Description: Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.
Family: unix Class: vulnerability
Reference(s): CVE-2009-2682
Version: 8
Platform(s): HP-UX 11
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 2

OpenVAS Exploits

Date Description
2009-10-14 Name : HP-UX Update for Role-Based Access Control (RBAC) HPSBUX02457
File : nvt/gb_hp_ux_HPSBUX02457.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
58351 HP-UX Role-Based Access Control (RBAC) Unspecified Local Access Restriction B...

Nessus® Vulnerability Scanner

Date Description
2009-09-28 Name : The remote HP-UX host is missing a security-related patch.
File : hpux_PHCO_40131.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:38:32
  • Multiple Updates