First published: Tue Nov 24 2009(Updated: )
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Operations Manager I | =8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3843 has a medium severity rating due to its potential for allowing remote attackers to execute arbitrary code.
To fix CVE-2009-3843, ensure that you are using a patched version of HP Operations Manager and review user access controls.
CVE-2009-3843 can lead to unauthorized file uploads and arbitrary code execution on affected systems.
While there have been indications of CVE-2009-3843 being exploited, it is recommended to secure systems proactively.
CVE-2009-3843 specifically affects HP Operations Manager version 8.10 on Windows platforms.