First published: Sat Mar 14 2015(Updated: )
HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Operations Manager i Management Pack | =1.0 | |
SAP NetWeaver |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2107 is classified as a medium severity vulnerability due to its potential to allow local users to execute arbitrary OS commands.
To remediate CVE-2015-2107, update to HP Operations Manager i Management Pack version 1.01 or later.
Local users of HP Operations Manager i Management Pack version 1.0 are affected by CVE-2015-2107.
The vulnerability may allow unauthorized local users to execute operating system commands with elevated SAP administrative privileges.
CVE-2015-2107 is associated with SAP environments as it leverages SAP administrative privileges, but SAP NetWeaver itself is not vulnerable.