int(5185)

Vulnerability Bulletins


Cross-Site Scripting en HP Project and Portfolio Management Center

Vulnerability classification

Property Value
Confidence level Oficial
Impact Aumento de la visibilidad
Dificulty Avanzado
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Comercial Software
Affected software HP Project and Portfolio Management Center

Description

Se ha descubierto una vulnerabilidad de tipo Cross-Site Scripting en HP Project and Portfolio Management Center 7.1 y 7.5.

Un atacante remoto podría inyectar código web script o HTML arbitrario mediante métodos no determinados.

Solution



Actualización de software

Hewlett-Packard
AIX: 5.2 & 5.3
PPMC 7.1 / PPMC_00085 o posterior
PPMC 7.5 / PPMC_00083 o posterior
HP-UX: 11.23
PPMC 7.1 / PPMC_00085 o posterior
PPMC 7.5 / PPMC_00083 o posterior
RedHat Linux 3.0AS & 4AS
PPMC 7.1 / PPMC_00085 o posterior
PPMC 7.5 / PPMC_00083 o posterior
Suse Linux: SLES9
PPMC 7.1 / PPMC_00085 o posterior
PPMC 7.5 / PPMC_00083 o posterior
Sparc Solaris: 9 & 10
PPMC 7.1 / PPMC_00085 o posterior
PPMC 7.5 / PPMC_00083 o posterior
Windows: 2003
PPMC 7.1 / PPMC_00085 o posterior
PPMC 7.5 / PPMC_00083 o posterior

Standar resources

Property Value
CVE CVE-2010-0452
BID NULL

Other resources

HP SECURITY BULLETIN (HPSBMA02436)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01762443

Version history

Version Comments Date
1.0 Aviso emitido 2010-04-05