CVE-2011-2608: Input Validation
ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2608?
CVE-2011-2608 is considered a critical vulnerability due to its ability to allow remote attackers to delete arbitrary files.
How do I fix CVE-2011-2608?
To fix CVE-2011-2608, upgrade to a patched version of HP OpenView Performance Agent or HP Operations Agent that is not affected by this vulnerability.
What are the affected versions for CVE-2011-2608?
CVE-2011-2608 affects HP OpenView Performance Agent versions 4.70 and 5.0, as well as HP Operations Agent versions 8.53, 8.60.005 through 8.60.008, 8.60.501, and 11.0.
Can CVE-2011-2608 impact my system security?
Yes, CVE-2011-2608 can significantly impact system security by allowing unauthorized deletion of files, potentially leading to data loss.
Is there a workaround for CVE-2011-2608 if I cannot update immediately?
A potential workaround for CVE-2011-2608 is to restrict access to the vulnerable components or to apply strict file permission controls until an update can be performed.