PT-2011-1228 · Hewlett Packard+1 · Hp Application Lifecycle Management+1
Published
2011-12-14
·
Updated
2018-12-11
·
CVE-2011-4834
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP Application Lifestyle Management (ALM) 11
Description
The issue is related to the
GetInstalledPackages function in the configuration tool, which lacks proper privilege control and access management mechanisms. This can allow an attacker to gain unauthorized access to confidential data, cause a denial of service, or impact data integrity. The vulnerability can be exploited by local users through specific methods, including the use of a Trojan horse /tmp/tmp.txt FIFO or a symlink attack on /tmp/tmp.txt.Recommendations
For HP Application Lifestyle Management (ALM) 11, consider restricting access to the
GetInstalledPackages function until a patch is available. As a temporary workaround, avoid using the /tmp/tmp.txt file in the configuration tool to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Hp Application Lifecycle Management