Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.801388
Categoría:Web application abuses
Título:HP OpenView Network Node Manager Multiple Code Execution Vulnerabilities
Resumen:HP OpenView Network Node Manager is prone to multiple code execution vulnerabilities.
Descripción:Summary:
HP OpenView Network Node Manager is prone to multiple code execution vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- A buffer overflow error in 'CGI' executable when processing an overly long
parameter value.

- A buffer overflow error in the 'ov.dll' library when processing certain
arguments supplied via CGI executables.

- An error in 'webappmon.exe' CGI application, which fails to adequately
validate user-supplied input.

Vulnerability Impact:
Successful exploitation will allow attacker to execute arbitrary code in
the context of an application.

Affected Software/OS:
HP OpenView Network Node Manager 7.51 and 7.53

Solution:
Upgrade to NNM v7.53 and apply the patch from the linked references.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-2704
BugTraq ID: 41839
http://www.securityfocus.com/bid/41839
Bugtraq: 20100721 VUPEN Security Research - HP OpenView Network Node Manager "nnmrptconfig.exe" Buffer Overflow (CVE-2010-2703) (Google Search)
http://www.securityfocus.com/archive/1/512543/100/0/threaded
HPdes Security Advisory: HPSBMA02558
http://marc.info/?l=bugtraq&m=127972286628707&w=2
HPdes Security Advisory: SSRT010158
HPdes Security Advisory: SSRT100158
http://marc.info/?l=bugtraq&m=127974889107645&w=2
http://secunia.com/advisories/40697
http://www.attrition.org/pipermail/vim/2010-July/002374.html
http://www.vupen.com/english/advisories/2010/1866
Common Vulnerability Exposure (CVE) ID: CVE-2010-2709
BugTraq ID: 42154
http://www.securityfocus.com/bid/42154
http://www.exploit-db.com/exploits/14547
HPdes Security Advisory: HPSBMA02563
http://seclists.org/bugtraq/2010/Aug/21
HPdes Security Advisory: SSRT100165
http://www.coresecurity.com/content/hp-nnm-ovjavalocale-buffer-overflow
http://securitytracker.com/id?1024274
http://securityreason.com/securityalert/8150
XForce ISS Database: hp-ovnnm-ovjavalocale-bo(60880)
https://exchange.xforce.ibmcloud.com/vulnerabilities/60880
CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.