CVE-2009-3843
Published Nov 24, 2009
Last updated 7 years ago
Overview
- Description
- HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
- Source
- hp-security-alert@hp.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hp:operations_manager:8.10:*:windows:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94949E33-6ED5-4E91-ABBD-353285AC3EF9" } ], "operator": "OR" } ] } ]