PT-2011-1228 · Hewlett Packard+1 · Hp Application Lifecycle Management+1

Published

2011-12-14

·

Updated

2018-12-11

·

CVE-2011-4834

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Application Lifestyle Management (ALM) 11
Description The issue is related to the GetInstalledPackages function in the configuration tool, which lacks proper privilege control and access management mechanisms. This can allow an attacker to gain unauthorized access to confidential data, cause a denial of service, or impact data integrity. The vulnerability can be exploited by local users through specific methods, including the use of a Trojan horse /tmp/tmp.txt FIFO or a symlink attack on /tmp/tmp.txt.
Recommendations For HP Application Lifestyle Management (ALM) 11, consider restricting access to the GetInstalledPackages function until a patch is available. As a temporary workaround, avoid using the /tmp/tmp.txt file in the configuration tool to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2754
ALT-PU-2018-2755
ALT-PU-2018-2814
BDU:2020-02951
CVE-2011-4834

Affected Products

Alt Linux
Hp Application Lifecycle Management