PT-2011-1228 · Hewlett Packard+1 · Hp Application Lifecycle Management+1

Publicado

2011-12-14

·

Atualizado

2018-12-11

·

CVE-2011-4834

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Application Lifestyle Management (ALM) 11
Description The issue is related to the GetInstalledPackages function in the configuration tool, which lacks proper privilege control and access management mechanisms. This can allow an attacker to gain unauthorized access to confidential data, cause a denial of service, or impact data integrity. The vulnerability can be exploited by local users through specific methods, including the use of a Trojan horse /tmp/tmp.txt FIFO or a symlink attack on /tmp/tmp.txt.
Recommendations For HP Application Lifestyle Management (ALM) 11, consider restricting access to the GetInstalledPackages function until a patch is available. As a temporary workaround, avoid using the /tmp/tmp.txt file in the configuration tool to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2754
ALT-PU-2018-2755
ALT-PU-2018-2814
BDU:2020-02951
CVE-2011-4834

Produtos afetados

Alt Linux
Hp Application Lifecycle Management