HP NonStop Server Unauthorized Directory Access Vulnerability
BID:20824
Info
HP NonStop Server Unauthorized Directory Access Vulnerability
| Bugtraq ID: | 20824 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 26 2006 12:00AM |
| Updated: | Oct 31 2006 09:57PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
HP NonStop Server G06.29 |
| Not Vulnerable: |
HP NonStop Server G06.29.02 |
Discussion
HP NonStop Server Unauthorized Directory Access Vulnerability
HP Nonstop Server is prone to a vulnerability that may permit unauthorized access to OSS directories.
Information the attacker obtains by accessing OSS directories may aid in further attacks.
HP Nonstop Server is prone to a vulnerability that may permit unauthorized access to OSS directories.
Information the attacker obtains by accessing OSS directories may aid in further attacks.
Exploit / POC
HP NonStop Server Unauthorized Directory Access Vulnerability
An attacker must have local interactive access to exploit this issue.
An attacker must have local interactive access to exploit this issue.
Solution / Fix
HP NonStop Server Unauthorized Directory Access Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the referenced advisory for more information.
Solution:
The vendor has released an update to address this issue. Please see the referenced advisory for more information.
References
HP NonStop Server Unauthorized Directory Access Vulnerability
References:
References:
- HP NonStop Server Home Page (Hewlett-Packard )
- HP Security Advisory HPSBNS02166 SSRT061255 rev.1 - HP NonStop Server running G0 (Hewlett-Packard )