First published: Wed Jul 21 2004(Updated: )
HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenView | =5.0-patch_4 | |
HP OpenView | =5.1-patch_1 | |
HP OpenView | =5.2 | |
HP OpenView | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0709 has been assessed as a medium severity vulnerability due to its potential for unauthorized access.
To mitigate CVE-2004-0709, apply the latest patches provided by HP for OpenView Select Access versions 5.0 through 6.0.
CVE-2004-0709 affects HP OpenView Select Access versions 5.0-patch_4, 5.1-patch_1, 5.2, and 6.0.
CVE-2004-0709 could allow remote attackers to bypass access restrictions using malformed UTF-8 encoded URLs.
CVE-2004-0709 can be easily exploited by attackers familiar with the encoding methods used in URLs.