First published: Fri Apr 29 2011(Updated: )
Cross-site request forgery (CSRF) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Systems Insight Manager | =4.1 | |
HP Systems Insight Manager | =2.5 | |
HP Systems Insight Manager | =4.2 | |
HP Systems Insight Manager | =4.2-sp1 | |
HP Systems Insight Manager | =6.0 | |
HP Systems Insight Manager | =6.1 | |
HP Systems Insight Manager | =5.0-sp5 | |
HP Systems Insight Manager | =5.0-sp3 | |
HP Systems Insight Manager | =5.0-sp4 | |
HP Systems Insight Manager | =5.1 | |
HP Systems Insight Manager | =5.3 | |
HP Systems Insight Manager | =4.1-sp1 | |
HP Systems Insight Manager | <=6.2 | |
HP Systems Insight Manager | =5.0-sp2 | |
HP Systems Insight Manager | =2.5.2.0 | |
HP Systems Insight Manager | =4.2-sp2 | |
HP Systems Insight Manager | =5.2-update_1 | |
HP Systems Insight Manager | =4.0-sp1 | |
HP Systems Insight Manager | =5.2 | |
HP Systems Insight Manager | =5.3-update_1 | |
HP Systems Insight Manager | =5.0 | |
HP Systems Insight Manager | =4.0 | |
HP Systems Insight Manager | =5.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1543 has been classified as a high severity vulnerability due to its potential for exploitation through cross-site request forgery.
To address CVE-2011-1543, upgrade HP Systems Insight Manager to version 6.3 or later.
CVE-2011-1543 affects multiple versions of HP Systems Insight Manager, including 2.5, 4.0 to 4.2, and all releases prior to 6.3.
CVE-2011-1543 involves a cross-site request forgery (CSRF) attack that allows attackers to hijack user sessions.
Any user of the affected versions of HP Systems Insight Manager is at risk of being targeted by this vulnerability.