PT-2007-6450 · Hewlett Packard · Hp Openview Configuration Management (Cm) Infrastructure+1
Publicado
2007-10-29
·
Atualizado
2018-10-15
·
CVE-2007-5413
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure versions 4.0 through 4.2i
Hewlett-Packard (HP) Client Configuration Manager (CCM) version 2.0
Description:
The issue allows remote attackers to read arbitrary files via URLs containing tilde (~) references to home directories. This is demonstrated by accessing the ~root directory.
Recommendations:
For Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure versions 4.0 through 4.2i, restrict access to URLs containing tilde () references to prevent arbitrary file reading.
For Hewlett-Packard (HP) Client Configuration Manager (CCM) version 2.0, avoid using URLs with tilde () references to home directories until the issue is resolved.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hp Client Configuration Manager
Hp Openview Configuration Management (Cm) Infrastructure