CVE-2009-3843: Critical severity micro focus operations manager i vulnerability
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3843?
CVE-2009-3843 has a medium severity rating due to its potential for allowing remote attackers to execute arbitrary code.
How can I fix CVE-2009-3843?
To fix CVE-2009-3843, ensure that you are using a patched version of HP Operations Manager and review user access controls.
What impact does CVE-2009-3843 have on my system?
CVE-2009-3843 can lead to unauthorized file uploads and arbitrary code execution on affected systems.
Is CVE-2009-3843 being actively exploited in the wild?
While there have been indications of CVE-2009-3843 being exploited, it is recommended to secure systems proactively.
What versions of HP Operations Manager are affected by CVE-2009-3843?
CVE-2009-3843 specifically affects HP Operations Manager version 8.10 on Windows platforms.