First published: Tue Feb 09 2010(Updated: )
HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Operations Agent | =8.51 | |
HP Operations Agent | =8.52 | |
HP Operations Agent | =8.53 | |
HP Operations Agent | =8.60 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 | |
All of | ||
Any of | ||
HP Operations Agent | =8.51 | |
HP Operations Agent | =8.52 | |
HP Operations Agent | =8.53 | |
HP Operations Agent | =8.60 | |
Any of | ||
Oracle Solaris and Zettabyte File System (ZFS) | =10 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0444 has been assigned a high severity due to the use of a blank password for the opc_op account, allowing potential unauthorized access.
To fix CVE-2010-0444, set a strong, non-blank password for the opc_op account in HP Operations Agent.
CVE-2010-0444 affects HP Operations Agent versions 8.51, 8.52, 8.53, and 8.60 on Solaris 10.
Organizations using HP Operations Agent versions 8.51, 8.52, and 8.53 on Solaris 10 are at risk due to CVE-2010-0444.
CVE-2010-0444 exposes systems to remote code execution vulnerabilities due to weak authentication mechanisms.