HP Service Manager Multiple Vulnerabilities
Last Update Date:
2 May 2013 11:28
Release Date:
2 May 2013
4118
Views
RISK: High Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities have been identified in HP Service Manager, which can be exploited by attacker to gain escalated privileges, conduct cross-site scripting attacks, disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
- The application bundles a vulnerable version of Java.
This vulnerabilities are identified in HP Service Manager versions 9.30 and 9.31 for Windows, Linux, HP-UX, Solaris, and AIX. - Certain unspecified input related to the Web Tier component is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
- An unspecified error in the Web Tier component can be exploited to disclose certain potentially sensitive information.
The vulnerabilities 2 and 3 are identified in version 9.31 for Windows.
Impact
- Cross-Site Scripting
- Denial of Service
- Elevation of Privilege
- Information Disclosure
System / Technologies affected
- HP Service Manager 9.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 9.31.2004 p2
Vulnerability Identifier
- CVE-2012-1541
- CVE-2012-1543
- CVE-2012-3213
- CVE-2012-3342
- CVE-2012-4301
- CVE-2012-4305
- CVE-2012-5222
- CVE-2013-0169
- CVE-2013-0351
- CVE-2013-0409
- CVE-2013-0419
- CVE-2013-0423
- CVE-2013-0424
- CVE-2013-0425
- CVE-2013-0426
- CVE-2013-0427
- CVE-2013-0428
- CVE-2013-0429
- CVE-2013-0430
- CVE-2013-0431
- CVE-2013-0432
- CVE-2013-0433
- CVE-2013-0434
- CVE-2013-0435
- CVE-2013-0436
- CVE-2013-0437
- CVE-2013-0438
- CVE-2013-0439
- CVE-2013-0440
- CVE-2013-0441
- CVE-2013-0442
- CVE-2013-0443
- CVE-2013-0444
- CVE-2013-0445
- CVE-2013-0446
- CVE-2013-0447
- CVE-2013-0448
- CVE-2013-0449
- CVE-2013-0450
- CVE-2013-1472
- CVE-2013-1473
- CVE-2013-1474
- CVE-2013-1475
- CVE-2013-1476
- CVE-2013-1477
- CVE-2013-1478
- CVE-2013-1479
- CVE-2013-1480
- CVE-2013-1481
- CVE-2013-1482
- CVE-2013-1483
- CVE-2013-1484
- CVE-2013-1485
- CVE-2013-1486
- CVE-2013-1487
- CVE-2013-1489
- CVE-2013-2321
Source
Related Link
Share with