Vulnerabilidad crítica en HP Business Service Management (BSM)
|
Vulnerability classification
|
|
Property |
Value |
|
Confidence level |
Oficial |
|
Impact |
Obtener acceso |
|
Dificulty |
Experto |
|
Required attacker level |
Acceso remoto sin cuenta a un servicio exotico |
System information
|
|
Property |
Value |
|
Affected manufacturer |
Comercial Software |
|
Affected software |
Business Service Management (BSM) v9.12 y versiones anteriores en Windows y Solaris |
Description
|
Se ha descubierto una vulnerabilidad de seguridad crítica en HP Business
Service Management (BSM), que podría permitir a un atacante remoto consultar y modificar información confidencial sin autorización, y efectuar ataques de denegación de servicio. |
Solution
|
|
Esta vulnerabilidad se puede evitar mediante la aplicación de reglas de firewall para bloquear el tráfico de fuentes no confiables a los puertos TCP de JBoss 4444, 1098, 1099. |
Standar resources
|
|
Property |
Value |
|
CVE |
CVE-2012-2561 |
|
BID |
|
Other resources
|
HP Business Service Management (BSM), Remote Unauthorized Disclosure of Information, Unauthorized Modification, Denial of Service (DoS) HPSBMU02792 SSRT100820 rev.1
https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03377648 |