First published: Thu Jan 13 2011(Updated: )
The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenView Network Node Manager | =7.51 | |
HP OpenView Network Node Manager | =7.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0271 has been classified as critical due to its potential for remote code execution.
To mitigate CVE-2011-0271, upgrade HP OpenView Network Node Manager to version 7.54 or later.
CVE-2011-0271 affects HP OpenView Network Node Manager versions 7.51 and 7.53.
Yes, CVE-2011-0271 can be exploited remotely by attackers to execute arbitrary commands.
CVE-2011-0271 is a command injection vulnerability due to improper validation of an unspecified parameter.