Skip to main content

HP OpenView Network Node Manager Multiple Remote Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 8 Jan 2009 5300 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in HP OpenView Network Node Manager (NNM), which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by buffer overflow errors in the "OpenView5.exe", "getcvdata.exe", "ovlaunch.exe", and "Toolbar.exe" CGI applications when processing overly long parameter strings, which could allow attackers to crash an affected application or execute arbitrary code via a specially crafted HTTP request.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • HP OpenView Network Node Manager (NNM) versions 7.x

Solutions

Restrict access to all affected CGI applications.


Vulnerability Identifier


Source


Related Link