CVE-2008-4559
Summary
| CVE | CVE-2008-4559 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-02-08 21:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via shell metacharacters in argument fields to the (1) webappmon.exe or (2) OpenView5.exe CGI program. NOTE: this issue may be partially covered by CVE-2009-0205. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hp | Openview Network Node Manager | 7.0.1 | All | hp_ux | All |
| Application | Hp | Openview Network Node Manager | 7.0.1 | All | linux | All |
| Application | Hp | Openview Network Node Manager | 7.0.1 | All | solaris | All |
| Application | Hp | Openview Network Node Manager | 7.0.1 | All | windows | All |
| Application | Hp | Openview Network Node Manager | 7.51 | - | hp-ux | All |
| Application | Hp | Openview Network Node Manager | 7.51 | - | linux | All |
| Application | Hp | Openview Network Node Manager | 7.51 | - | solaris | All |
| Application | Hp | Openview Network Node Manager | 7.51 | - | windows | All |
| Application | Hp | Openview Network Node Manager | 7.53 | - | hp-ux | All |
| Application | Hp | Openview Network Node Manager | 7.53 | - | linux | All |
| Application | Hp | Openview Network Node Manager | 7.53 | - | solaris | All |
| Application | Hp | Openview Network Node Manager | 7.53 | - | windows | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HPSBMA02406 SSRT080100 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code - c01661610 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| Public Advisory: 02.06.09 // iDefense Labs | af854a3a-2127-422b-91ae-364da2661108 | labs.idefense.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.