CVE-2009-3845: Critical severity hewlett packard openview network node manager vulnerability
The port-3443 HTTP server in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostname parameter to unspecified Perl scripts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2009-3845?
CVE-2009-3845 is a vulnerability in HP OpenView Network Node Manager that allows remote attackers to execute arbitrary commands via shell metacharacters in the hostname parameter.
What versions of HP OpenView Network Node Manager are affected by CVE-2009-3845?
The impacted versions are 7.01, 7.51, and 7.53 for various operating systems including Windows, Solaris, Linux, and HP-UX.
What is the potential impact of exploiting CVE-2009-3845?
Exploitation of CVE-2009-3845 could allow an attacker to execute arbitrary commands on the affected systems, leading to unauthorized access and control.
How can CVE-2009-3845 be mitigated?
To mitigate CVE-2009-3845, it is recommended to upgrade to a patched version of HP OpenView Network Node Manager that resolves this vulnerability.
Is there a known fix for CVE-2009-3845?
Yes, the recommended action is to update to a version of HP OpenView Network Node Manager that does not contain this vulnerability.