int(6341)

Vulnerability Bulletins


Vulnerabilidad crítica en HP Business Service Management (BSM)

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer Comercial Software
Affected software Business Service Management (BSM) v9.12 y versiones anteriores en Windows y Solaris

Description

Se ha descubierto una vulnerabilidad de seguridad crítica en HP Business
Service Management (BSM), que podría permitir a un atacante remoto consultar y modificar información confidencial sin autorización, y efectuar ataques de denegación de servicio.

Solution

Esta vulnerabilidad se puede evitar mediante la aplicación de reglas de firewall para bloquear el tráfico de fuentes no confiables a los puertos TCP de JBoss 4444, 1098, 1099.

Standar resources

Property Value
CVE CVE-2012-2561
BID

Other resources

HP Business Service Management (BSM), Remote Unauthorized Disclosure of Information, Unauthorized Modification, Denial of Service (DoS) HPSBMU02792 SSRT100820 rev.1
https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03377648

Version history

Version Comments Date
1.0 Aviso emitido 2012-06-25