HP OpenView Network Node Manager Unspecified Cross-Site Scripting Vulnerability
BID:26637
Info
HP OpenView Network Node Manager Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 26637 |
| Class: | Unknown |
| CVE: |
CVE-2007-6343 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2007 12:00AM |
| Updated: | Jan 29 2008 06:07PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Nortel Networks Multiservice Data Manager 0 Nortel Networks Enterprise NMS 0 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.01 HP OpenView Network Node Manager 6.41 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager Unspecified Cross-Site Scripting Vulnerability
HP OpenView Network Node Manager is prone to an unspecified cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects HP OpenView Network Node Manager 6.41, 7.01, and 7.51.
HP OpenView Network Node Manager is prone to an unspecified cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects HP OpenView Network Node Manager 6.41, 7.01, and 7.51.
Exploit / POC
HP OpenView Network Node Manager Unspecified Cross-Site Scripting Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP OpenView Network Node Manager Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
HP OpenView Network Node Manager 7.01
HP OpenView Network Node Manager 6.41
HP OpenView Network Node Manager 7.51
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
HP OpenView Network Node Manager 7.01
-
HP NNM_01159
Windows
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36773
HP-UX B.11.00
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36773
HP-UX B.11.11
http://support.openview.hp.com/patches/patch_index.jsp -
HP PSOV_03480
Solaris
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 6.41
-
HP NNM_01167
Windows
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_37141
HP-UX B.11.00
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_37141
HP-UX B.11.11
http://support.openview.hp.com/patches/patch_index.jsp -
HP PSOV_03489
Solaris
http://support.openview.hp.com/patches/patch_index.jsp
HP OpenView Network Node Manager 7.51
-
HP LXOV_00054
Linux RedHatAS2.1
http://support.openview.hp.com/patches/patch_index.jsp -
HP NNM_01161
Windows
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36901
HP-UX B.11.00
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36901
HP-UX B.11.11
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36901
HP-UX B.11.23 (PA)
http://support.openview.hp.com/patches/patch_index.jsp -
HP PHSS_36902
HP-UX B.11.23 (IA)
http://support.openview.hp.com/patches/patch_index.jsp -
HP PSOV_03482
Solaris
http://support.openview.hp.com/patches/patch_index.jsp
References
HP OpenView Network Node Manager Unspecified Cross-Site Scripting Vulnerability
References:
References: