First published: Sun Feb 08 2009(Updated: )
HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to obtain sensitive information via (1) a crafted request to the nnmRptConfig.exe CGI program, which reveals the pathname of log directories; or (2) a crafted parameter in a request to the ovlaunch.exe CGI program, which reveals configuration details. NOTE: this issue may be partially covered by CVE-2009-0205.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.53 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4560 is classified as a medium severity vulnerability.
To mitigate CVE-2008-4560, update HP OpenView Network Node Manager to the latest version or apply available patches.
CVE-2008-4560 allows remote attackers to obtain sensitive information such as log directory paths.
CVE-2008-4560 affects HP OpenView Network Node Manager versions 7.01, 7.51, and 7.53.
Yes, attackers can exploit CVE-2008-4560 by sending crafted requests to specific CGI programs in the software.