CVE-1999-0707: High severity HP Visualize Conference Ftp vulnerability

Published Jul 1, 1999
·
Updated

The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.

Affected Software

2 affected components
HP Visualize Conference Ftp
HP HP-UX=10.20

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove HP Visualize Conference FTP/file-transfer component from your environment.

    If file transfer functionality is not required, disable or uninstall the FTP/file-transfer component to eliminate the unauthorized transfer capability.

  2. Configuration

    Change the default FTP/file-transfer configuration so that sending files between conference participants requires authentication. Do not allow anonymous or unauthenticated file transfers.

    HP Visualize Conference FTP/file-transfer subsystem require_authentication_for_file_transfers = true
  3. Compensating control

    Until the configuration is changed or the component removed, block or restrict access to the FTP/file-transfer service (for example, via firewall rules or network ACLs restricting to trusted management hosts) or disable the file-transfer feature to prevent unauthorized file sends.

Event History

Jul 1, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0707?

CVE-1999-0707 is considered a moderate severity vulnerability due to unauthorized file transfer capabilities in the default FTP configuration.

2

How do I fix CVE-1999-0707?

To fix CVE-1999-0707, you should update the FTP configuration to restrict file transfer permissions and ensure proper authorization is required.

3

What software does CVE-1999-0707 affect?

CVE-1999-0707 affects HP Visualize Conference FTP and HP-UX version 10.20.

4

Can CVE-1999-0707 lead to data leaks?

Yes, CVE-1999-0707 can lead to unauthorized data leakage as users may send files to others without proper authentication.

5

Is authentication required for file transfers in CVE-1999-0707?

No, authentication is not required by default in the FTP configuration affected by CVE-1999-0707.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203