Skip to main content

HP OpenView Performance Insight Server Hiden Account Vulnerability

Last Update Date: 2 Feb 2011 15:42 Release Date: 2 Feb 2011 6121 Views

RISK: High Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability has been identified in HP OpenView Performance Insight Server, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused due to a hidden account present within the "com.trinagy.security.XMLUserManager" Java class, which could allow remote attackers to upload malicious files on a vulnerable server and execute arbitrary code with elevated privileges.


Impact

  • Remote Code Execution

System / Technologies affected

  • HP OpenView Performance Insight Server version 5.2
  • HP OpenView Performance Insight Server version 5.3
  • HP OpenView Performance Insight Server version 5.31
  • HP OpenView Performance Insight Server version 5.4
  • HP OpenView Performance Insight Server version 5.41

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • HP OpenView Performance Insight Server v5.4 and v5.41 - Contact the normal HP Services support channel to request the "5.41.002 piweb HF02" hotfix
  • HP OpenView Performance Insight Server v5.2, v5.3 and v5.31 - Upgrade to HP OpenView Performance Insight Server 5.41 and contact the normal HP Services support channel to request the "5.41.002 piweb HF02" hotfix
  • http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02695453

Vulnerability Identifier


Source


Related Link