HP OpenView Performance Insight Server Hiden Account Vulnerability
RISK: High Risk
TYPE: Servers - Network Management
A vulnerability has been identified in HP OpenView Performance Insight Server, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused due to a hidden account present within the "com.trinagy.security.XMLUserManager" Java class, which could allow remote attackers to upload malicious files on a vulnerable server and execute arbitrary code with elevated privileges.
Impact
- Remote Code Execution
System / Technologies affected
- HP OpenView Performance Insight Server version 5.2
- HP OpenView Performance Insight Server version 5.3
- HP OpenView Performance Insight Server version 5.31
- HP OpenView Performance Insight Server version 5.4
- HP OpenView Performance Insight Server version 5.41
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- HP OpenView Performance Insight Server v5.4 and v5.41 - Contact the normal HP Services support channel to request the "5.41.002 piweb HF02" hotfix
- HP OpenView Performance Insight Server v5.2, v5.3 and v5.31 - Upgrade to HP OpenView Performance Insight Server 5.41 and contact the normal HP Services support channel to request the "5.41.002 piweb HF02" hotfix
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02695453
Vulnerability Identifier
Source
Related Link
Share with