HP System Management Homepage Unspecified Security Bypass Vulnerability
BID:32088
Info
HP System Management Homepage Unspecified Security Bypass Vulnerability
| Bugtraq ID: | 32088 |
| Class: | Unknown |
| CVE: |
CVE-2008-4413 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 03 2008 12:00AM |
| Updated: | Nov 12 2008 04:54PM |
| Credit: | HP |
| Vulnerable: |
HP System Management Homepage 2.2.8 HP System Management Homepage 2.2.6 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 |
| Not Vulnerable: |
HP System Management Homepage 2.2.9 .1 |
Discussion
HP System Management Homepage Unspecified Security Bypass Vulnerability
HP System Management Homepage (SMH) is prone to a security-bypass vulnerability caused by an unspecified error.
Attackers can leverage this issue to gain local unauthorized access.
The following products are vulnerable:
SMH 2.2.6 and earlier running on HP-UX B.11.11 and B.11.23
SMH 2.2.6 and v2.2.8 and earlier running on HP-UX B.11.23 and B.11.31
HP System Management Homepage (SMH) is prone to a security-bypass vulnerability caused by an unspecified error.
Attackers can leverage this issue to gain local unauthorized access.
The following products are vulnerable:
SMH 2.2.6 and earlier running on HP-UX B.11.11 and B.11.23
SMH 2.2.6 and v2.2.8 and earlier running on HP-UX B.11.23 and B.11.31
Exploit / POC
HP System Management Homepage Unspecified Security Bypass Vulnerability
Attackers will likely exploit this issue using standard tools and commands.
Attackers will likely exploit this issue using standard tools and commands.
Solution / Fix
HP System Management Homepage Unspecified Security Bypass Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
HP System Management Homepage Unspecified Security Bypass Vulnerability
References:
References: