HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities
BID:50471
Info
HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 50471 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3166 CVE-2011-3167 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2011 12:00AM |
| Updated: | Jan 20 2012 04:50PM |
| Credit: | [email protected] and TippingPoint's Zero Day Initiative |
| Vulnerable: |
HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities
HP OpenView Network Node Manager (NNM) is prone to multiple remote code-execution vulnerabilities because it fails to sanitize user-supplied data.
An attacker can exploit these issues to execute arbitrary code with the privileges of the user running the affected application. Successful exploits will compromise the affected application and possibly the underlying computer.
These issues affects NNM 7.51, v7.53 running on HP-UX, Linux, Solaris, and Windows; other versions and platforms may also be affected.
HP OpenView Network Node Manager (NNM) is prone to multiple remote code-execution vulnerabilities because it fails to sanitize user-supplied data.
An attacker can exploit these issues to execute arbitrary code with the privileges of the user running the affected application. Successful exploits will compromise the affected application and possibly the underlying computer.
These issues affects NNM 7.51, v7.53 running on HP-UX, Linux, Solaris, and Windows; other versions and platforms may also be affected.
Exploit / POC
HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities
The following exploit is available:
The following exploit is available:
Solution / Fix
HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities
Solution:
Updates are available; please contact the vendor for more information.
Solution:
Updates are available; please contact the vendor for more information.
References
HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities
References:
References:
- HP OpenView Network Node Manager Product Page (HP)
- HP OpenView NNM ov.dll _OVBuildPath Remote Code Execution Vulnerability (TippingPoint Zero Day Initiative)
- HP OpenView NNM webappmon.exe parameter Remote Code Execution Vulnerability (TippingPoint Zero Day Initiative)
- HPSBMU02712 SSRT100649 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote ([email protected])