PT-2007-6450 · Hewlett Packard · Hp Openview Configuration Management (Cm) Infrastructure+1
Published
2007-10-29
·
Updated
2018-10-15
·
CVE-2007-5413
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure versions 4.0 through 4.2i
Hewlett-Packard (HP) Client Configuration Manager (CCM) version 2.0
Description:
The issue allows remote attackers to read arbitrary files via URLs containing tilde (~) references to home directories. This is demonstrated by accessing the ~root directory.
Recommendations:
For Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure versions 4.0 through 4.2i, restrict access to URLs containing tilde () references to prevent arbitrary file reading.
For Hewlett-Packard (HP) Client Configuration Manager (CCM) version 2.0, avoid using URLs with tilde () references to home directories until the issue is resolved.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Client Configuration Manager
Hp Openview Configuration Management (Cm) Infrastructure