HP Quality Center Cached Workflow Scripts Security Bypass Vulnerability
BID:33854
Info
HP Quality Center Cached Workflow Scripts Security Bypass Vulnerability
| Bugtraq ID: | 33854 |
| Class: | Design Error |
| CVE: |
CVE-2007-5289 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2009 12:00AM |
| Updated: | Feb 25 2009 10:57PM |
| Credit: | Valéry Raulet |
| Vulnerable: |
HP Quality Center 9.2 HP Quality Center 9.0 |
| Not Vulnerable: | |
Discussion
HP Quality Center Cached Workflow Scripts Security Bypass Vulnerability
HP Quality Center is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to overwrite content in the database, corrupt data, and carry out other attacks.
HP Quality Center 9.0 and 9.2 are vulnerable; other versions may be affected as well.
NOTE: Reports indicate that an exploit may not gain privileges.
HP Quality Center is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to overwrite content in the database, corrupt data, and carry out other attacks.
HP Quality Center 9.0 and 9.2 are vulnerable; other versions may be affected as well.
NOTE: Reports indicate that an exploit may not gain privileges.
Exploit / POC
HP Quality Center Cached Workflow Scripts Security Bypass Vulnerability
An attacker can use system utilities to carry out an attack.
An attacker can use system utilities to carry out an attack.
Solution / Fix
HP Quality Center Cached Workflow Scripts Security Bypass Vulnerability
Solution:
Reports indicated that the vendor has released a fix. Symantec has not verified this information. Please contact the vendor and see the references for more information.
Solution:
Reports indicated that the vendor has released a fix. Symantec has not verified this information. Please contact the vendor and see the references for more information.
References
HP Quality Center Cached Workflow Scripts Security Bypass Vulnerability
References:
References:
- HP Quality Center software (HP)
- Quality Center security issue (Valery Raulet)
- Vulnerability in Quality Center (Valery Raulet)
- HP Quality Center vulnerability ([email protected])
- Re: HP Quality Center vulnerability (Pavel Kankovsky
)