PT-2007-6450 · Hewlett Packard · Hp Openview Configuration Management (Cm) Infrastructure+1

Publicado

2007-10-29

·

Atualizado

2018-10-15

·

CVE-2007-5413

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure versions 4.0 through 4.2i Hewlett-Packard (HP) Client Configuration Manager (CCM) version 2.0
Description: The issue allows remote attackers to read arbitrary files via URLs containing tilde (~) references to home directories. This is demonstrated by accessing the ~root directory.
Recommendations: For Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure versions 4.0 through 4.2i, restrict access to URLs containing tilde () references to prevent arbitrary file reading. For Hewlett-Packard (HP) Client Configuration Manager (CCM) version 2.0, avoid using URLs with tilde () references to home directories until the issue is resolved.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5413

Produtos afetados

Hp Client Configuration Manager
Hp Openview Configuration Management (Cm) Infrastructure