![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2009-3843 |
Description: | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-3843 HPdes Security Advisory: HPSBMA02478 http://marc.info/?l=bugtraq&m=125873415424980&w=2 HPdes Security Advisory: SSRT090251 http://marc.info/?l=bugtraq&m=125873415424980&w=2 http://www.zerodayinitiative.com/advisories/ZDI-09-085/ http://www.osvdb.org/60317 http://securitytracker.com/id?1023222 http://secunia.com/advisories/37444 XForce ISS Database: operations-manager-unspecified-sec-bypass(54361) https://exchange.xforce.ibmcloud.com/vulnerabilities/54361 |