CVE-2007-5413

httpd.tkd in Radia Integration Server in Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure 4.0 through 4.2i and Client Configuration Manager (CCM) 2.0 allows remote attackers to read arbitrary files via URLs containing tilde (~) references to home directories, as demonstrated by ~root.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:openview_client_configuraton_manager:2.0:*:windows:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.0:*:aix:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.0:*:hpux:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.0:*:linux:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.0:*:solaris:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.0:*:windows:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.1:*:aix:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.1:*:hpux:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.1:*:linux:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.1:*:solaris:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.1:*:windows:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2:*:aix:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2:*:hpux:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2:*:linux:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2:*:solaris:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2:*:windows:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2i:*:aix:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2i:*:hpux:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2i:*:linux:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2i:*:solaris:*:*:*:*:*
cpe:2.3:a:hp:openview_configuration_management:4.2i:*:windows:*:*:*:*:*

History

21 Nov 2024, 00:37

Type Values Removed Values Added
References () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01205079 - () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01205079 -
References () http://osvdb.org/39528 - () http://osvdb.org/39528 -
References () http://secunia.com/advisories/27341 - Vendor Advisory () http://secunia.com/advisories/27341 - Vendor Advisory
References () http://www.securityfocus.com/archive/1/483106/100/100/threaded - () http://www.securityfocus.com/archive/1/483106/100/100/threaded -
References () http://www.securitytracker.com/id?1018858 - () http://www.securitytracker.com/id?1018858 -
References () http://www.vupen.com/english/advisories/2007/3620 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/3620 - Vendor Advisory
References () http://www.zerodayinitiative.com/advisories/ZDI-07-060.html - () http://www.zerodayinitiative.com/advisories/ZDI-07-060.html -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/37400 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/37400 -

Information

Published : 2007-10-29 22:46

Updated : 2024-11-21 00:37


NVD link : CVE-2007-5413

Mitre link : CVE-2007-5413

CVE.ORG link : CVE-2007-5413


JSON object : View

Products Affected

hp

  • openview_configuration_management
  • openview_client_configuraton_manager
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor