First published: Wed Feb 09 2011(Updated: )
Cross-site request forgery (CSRF) vulnerability in HP Power Manager (HPPM) 4.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Power Manager | <=4.3.2 | |
HP Power Manager | =4.2.5 | |
HP Power Manager | =4.2.8 | |
HP Power Manager | =4.2.6 | |
HP Power Manager | =4.2.9 | |
HP Power Manager | =4.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0277 is classified as a medium severity vulnerability due to its potential for unauthorized administrative access.
To fix CVE-2011-0277, users should upgrade to a version of HP Power Manager later than 4.3.2.
Attackers can exploit CVE-2011-0277 through cross-site request forgery (CSRF) to hijack administrator sessions.
CVE-2011-0277 affects HP Power Manager versions 4.3.2 and earlier.
Administrators of HP Power Manager are at risk of having their authentication compromised due to CVE-2011-0277.