{"api_version":"1","generated_at":"2026-07-23T19:55:21+00:00","cve":"CVE-2009-3843","urls":{"html":"https://cve.report/CVE-2009-3843","api":"https://cve.report/api/cve/CVE-2009-3843.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3843","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3843"},"summary":{"title":"CVE-2009-3843","description":"HP Operations Manager 8.10 on Windows contains a \"hidden account\" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.","state":"PUBLISHED","assigner":"hp","published_at":"2009-11-24 00:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.zerodayinitiative.com/advisories/ZDI-09-085/","name":"http://www.zerodayinitiative.com/advisories/ZDI-09-085/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37444","name":"http://secunia.com/advisories/37444","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HP Operations Manager Undocumented Account - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/60317","name":"http://www.osvdb.org/60317","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=125873415424980&w=2","name":"http://marc.info/?l=bugtraq&m=125873415424980&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[security bulletin] HPSBMA02478 SSRT090251 rev.1 - HP Operations Manager for Windows, Remote Unautho' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1023222","name":"http://securitytracker.com/id?1023222","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - HP Operations Manager Hidden Account Lets Remote Users Access the System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54361","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54361","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3843","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3843","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"operations_manager","cpe6":"8.10","cpe7":"*","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:38:30.345Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"HPSBMA02478","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=125873415424980&w=2"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-09-085/"},{"name":"operations-manager-unspecified-sec-bypass(54361)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54361"},{"name":"1023222","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1023222"},{"name":"SSRT090251","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=125873415424980&w=2"},{"name":"37444","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37444"},{"name":"60317","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/60317"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-11-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"HP Operations Manager 8.10 on Windows contains a \"hidden account\" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"74586083-13ce-40fd-b46a-8e5d23cfbcb2","shortName":"hp"},"references":[{"name":"HPSBMA02478","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=125873415424980&w=2"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-09-085/"},{"name":"operations-manager-unspecified-sec-bypass(54361)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54361"},{"name":"1023222","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1023222"},{"name":"SSRT090251","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=125873415424980&w=2"},{"name":"37444","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37444"},{"name":"60317","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/60317"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"hp-security-alert@hp.com","ID":"CVE-2009-3843","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"HP Operations Manager 8.10 on Windows contains a \"hidden account\" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"HPSBMA02478","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=125873415424980&w=2"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-09-085/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-09-085/"},{"name":"operations-manager-unspecified-sec-bypass(54361)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54361"},{"name":"1023222","refsource":"SECTRACK","url":"http://securitytracker.com/id?1023222"},{"name":"SSRT090251","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=125873415424980&w=2"},{"name":"37444","refsource":"SECUNIA","url":"http://secunia.com/advisories/37444"},{"name":"60317","refsource":"OSVDB","url":"http://www.osvdb.org/60317"}]}}}},"cveMetadata":{"assignerOrgId":"74586083-13ce-40fd-b46a-8e5d23cfbcb2","assignerShortName":"hp","cveId":"CVE-2009-3843","datePublished":"2009-11-24T00:00:00.000Z","dateReserved":"2009-11-02T00:00:00.000Z","dateUpdated":"2024-08-07T06:38:30.345Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-11-24 00:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:operations_manager:8.10:*:windows:*:*:*:*:*","matchCriteriaId":"94949E33-6ED5-4E91-ABBD-353285AC3EF9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3843","Ordinal":"1","Title":"CVE-2009-3843","CVE":"CVE-2009-3843","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3843","Ordinal":"1","NoteData":"HP Operations Manager 8.10 on Windows contains a \"hidden account\" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.","Type":"Description","Title":"CVE-2009-3843"},{"CveYear":"2009","CveId":"3843","Ordinal":"2","NoteData":"2009-11-23","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3843","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}