HP System Management Homepage Multiple Vulnerabilities
Last Update Date:
22 Jul 2013 10:54
Release Date:
22 Jul 2013
4145
Views
RISK: Medium Risk
TYPE: Servers - Network Management
Multiple vulnerabilities have been identified in HP System Management Homepage, which can be exploited by attackers to potentially gain escalated privileges, cause a DoS (Denial of Service), conduct cross-site scripting attacks, disclose certain sensitive information, hijack a user's session, and compromise a vulnerable system.
- Unspecified error can be exploited to disclose certain information.
- Unspecified error can be exploited to cause a DoS.
- Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Impact
- Cross-Site Scripting
- Denial of Service
- Elevation of Privilege
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- HP System Management Homepage 7.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 7.2.1 or later.
Vulnerability Identifier
- CVE-2011-3389
- CVE-2012-0883
- CVE-2012-2110
- CVE-2012-2311
- CVE-2012-2329
- CVE-2012-2335
- CVE-2012-2336
- CVE-2013-2355
- CVE-2013-2356
- CVE-2013-2357
- CVE-2013-2358
- CVE-2013-2359
- CVE-2013-2360
- CVE-2013-2361
- CVE-2013-2362
- CVE-2013-2363
- CVE-2013-2364
- CVE-2013-5217
Source
Related Link
Share with