HP OpenView Network Node Manager Multiple Remote Command Execution Vulnerabilities
BID:14662
Info
HP OpenView Network Node Manager Multiple Remote Command Execution Vulnerabilities
| Bugtraq ID: | 14662 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2005 12:00AM |
| Updated: | Dec 22 2006 12:02AM |
| Credit: | James Fisher of Portcullis Computer Security Ltd discovered the 'connectedNodes.ovpl' vulnerability. David Litchfield of NGS Software Ltd. also reported these issues to the vendor. |
| Vulnerable: |
HP OpenView Network Node Manager 7.50 Windows 2000/XP HP OpenView Network Node Manager 7.50 Solaris HP OpenView Network Node Manager 7.50 HP-UX 11.X HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.0 .1 Windows 2000/XP HP OpenView Network Node Manager 7.0 .1 Solaris HP OpenView Network Node Manager 7.0 .1 Linux HP OpenView Network Node Manager 7.0 .1 HP-UX 11.X HP OpenView Network Node Manager 7.0 .1 HP OpenView Network Node Manager 6.41 Solaris HP OpenView Network Node Manager 6.31 NT 4.X/Windows 2000 HP OpenView Network Node Manager 6.31 HP OpenView Network Node Manager 6.10 HP OpenView Network Node Manager 6.4 Solaris HP OpenView Network Node Manager 6.4 NT 4.X/Windows 2000 HP OpenView Network Node Manager 6.4 HP OpenView Network Node Manager 6.2 Solaris HP OpenView Network Node Manager 6.2 NT 4.X/Windows 2000 HP OpenView Network Node Manager 6.2 NT 4.X/Windows 2000 HP OpenView Network Node Manager 6.2 HP OpenView Network Node Manager 6.41 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager Multiple Remote Command Execution Vulnerabilities
HP OpenView Network Node Manager is prone to multiple remote arbitrary command-execution vulnerabilities.
These issue arise when the user-specified 'node' URI parameter of various scripts is used as part of a command to be executed with the 'system()' function.
These issues may facilitate unauthorized remote access in the context of the webserver to the affected computer.
These issues affect version 6.41 and 7.5 on the Solaris platform. Unknown versions of the package on Microsoft Windows platforms are also affected. Other versions and platforms are also likely affected.
HP OpenView Network Node Manager is prone to multiple remote arbitrary command-execution vulnerabilities.
These issue arise when the user-specified 'node' URI parameter of various scripts is used as part of a command to be executed with the 'system()' function.
These issues may facilitate unauthorized remote access in the context of the webserver to the affected computer.
These issues affect version 6.41 and 7.5 on the Solaris platform. Unknown versions of the package on Microsoft Windows platforms are also affected. Other versions and platforms are also likely affected.
Exploit / POC
HP OpenView Network Node Manager Multiple Remote Command Execution Vulnerabilities
An exploit is not required.
The following proof of concept is available:
http://www.example.com:3443/OvCgi/connectedNodes.ovpl?node=a| [your command] |
Proof of concept example 'hp_ovnnm_poc.c' has been provided by Lympex.
The openview_connectednodes_exec.pm exploit is available for the Metasploit framework.
An exploit is not required.
The following proof of concept is available:
http://www.example.com:3443/OvCgi/connectedNodes.ovpl?node=a| [your command] |
Proof of concept example 'hp_ovnnm_poc.c' has been provided by Lympex.
The openview_connectednodes_exec.pm exploit is available for the Metasploit framework.
Solution / Fix
HP OpenView Network Node Manager Multiple Remote Command Execution Vulnerabilities
Solution:
Please see the referenced advisories for information on updates.
HP OpenView Network Node Manager 7.0 .1
HP OpenView Network Node Manager 7.0 .1 Windows 2000/XP
HP OpenView Network Node Manager 7.0 .1 Solaris
HP OpenView Network Node Manager 7.0 .1 HP-UX 11.X
HP OpenView Network Node Manager 7.50 HP-UX 11.X
HP OpenView Network Node Manager 7.50 Solaris
HP OpenView Network Node Manager 7.50 Windows 2000/XP
HP OpenView Network Node Manager 7.50
Solution:
Please see the referenced advisories for information on updates.
HP OpenView Network Node Manager 7.0 .1
-
HP PHSS_33842
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 7.0 .1 Windows 2000/XP
HP OpenView Network Node Manager 7.0 .1 Solaris
-
HP PSOV_03430
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 7.0 .1 HP-UX 11.X
-
HP PHSS_33842
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 7.50 HP-UX 11.X
-
HP PHSS_33783
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_33784
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 7.50 Solaris
-
HP PSOV_03425
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 7.50 Windows 2000/XP
HP OpenView Network Node Manager 7.50
-
HP PHSS_33783
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_33784
http://support.openview.hp.com/patches/patch_index.jsp
References
HP OpenView Network Node Manager Multiple Remote Command Execution Vulnerabilities
References:
References:
- OpenView Homepage (HP)
- Portcullis Security Advisory 05-014 HP Openview Remote Command Execution Vuln ("Paul J Docherty"
) - Re: Portcullis Security Advisory 05-014 HP Openview Remote Command Execution ("David Litchfield"
)