CVE-2011-0277: CSRF
Published Feb 9, 2011
·Updated
Cross-site request forgery (CSRF) vulnerability in HP Power Manager (HPPM) 4.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.
Affected Software
6 affected components
hp Power Manager<=4.3.2
hp Power Manager=4.2.5
hp Power Manager=4.2.8
hp Power Manager=4.2.6
hp Power Manager=4.2.9
hp Power Manager=4.2.7
Event History
Feb 9, 2011
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0277?
CVE-2011-0277 is classified as a medium severity vulnerability due to its potential for unauthorized administrative access.
2
How do I fix CVE-2011-0277?
To fix CVE-2011-0277, users should upgrade to a version of HP Power Manager later than 4.3.2.
3
What types of attacks can exploit CVE-2011-0277?
Attackers can exploit CVE-2011-0277 through cross-site request forgery (CSRF) to hijack administrator sessions.
4
What systems are affected by CVE-2011-0277?
CVE-2011-0277 affects HP Power Manager versions 4.3.2 and earlier.
5
Who is at risk from CVE-2011-0277?
Administrators of HP Power Manager are at risk of having their authentication compromised due to CVE-2011-0277.