CVE-2008-4560

HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to obtain sensitive information via (1) a crafted request to the nnmRptConfig.exe CGI program, which reveals the pathname of log directories; or (2) a crafted parameter in a request to the ovlaunch.exe CGI program, which reveals configuration details. NOTE: this issue may be partially covered by CVE-2009-0205.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:hp_ux:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:linux:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:solaris:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:windows:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.51:-:hp-ux:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.51:-:linux:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.51:-:solaris:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.51:-:windows:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.53:-:hp-ux:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.53:-:linux:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.53:-:solaris:*:*:*:*:*
cpe:2.3:a:hp:openview_network_node_manager:7.53:-:windows:*:*:*:*:*

History

21 Nov 2024, 00:51

Type Values Removed Values Added
References () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01661610 - Patch, Vendor Advisory () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01661610 - Patch, Vendor Advisory
References () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=771 - () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=771 -

Information

Published : 2009-02-08 21:30

Updated : 2024-11-21 00:51


NVD link : CVE-2008-4560

Mitre link : CVE-2008-4560

CVE.ORG link : CVE-2008-4560


JSON object : View

Products Affected

hp

  • openview_network_node_manager
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor