Vulnerability Bulletins |
Múltiples vulnerabilidades en HP Performance Insight for Networks |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Avanzado |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | Comercial Software |
| Affected software | HP Performance Insight for Networks ejecutándose en HP-UX, Linux, Solaris, y Windows v5.3.x , v5.41, v5.41.001, v5.41.002 |
Description |
|
|
Se han descubierto varias vulnerabilidades en HP Performance Insight for Networks en HP-UX, Linux, Solaris y Windows. Estas vulnerabilidades son de tipo SQL Injection, XSS (Cross-site Scripting) y de elevación de privilegios, que podrían permitir a un atacante remoto ejecutar código arbitrario y obtener información privada. |
|
Solution |
|
| HP ha publicado una parche que soluciona estas vulnerabilidades. | |
Standar resources |
|
| Property | Value |
| CVE |
CVE-2011-2007 CVE-2011-2008 CVE-2011-2009 CVE-2012-2007 CVE-2012-2008 CVE-2012-2009 |
| BID | |
Other resources |
|
|
HP SUPPORT COMMUNICATION - SECURITY BULLETIN http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03312417 |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2012-05-17 |






