CVE-2011-4834: Medium severity hp application lifecycle management vulnerability
The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4834?
CVE-2011-4834 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2011-4834?
To fix CVE-2011-4834, ensure that the application is updated to the latest version and restrict access to the /tmp directory.
Who is affected by CVE-2011-4834?
CVE-2011-4834 affects local users of HP Application Lifecycle Management 11 on AIX, HP-UX, and Solaris.
What are the attack vectors for CVE-2011-4834?
The attack vectors for CVE-2011-4834 include exploiting a Trojan horse file and symlink attacks on /tmp/tmp.txt.
Can remote attackers exploit CVE-2011-4834?
No, CVE-2011-4834 is a local privilege escalation vulnerability that requires local user access to exploit.