Lucene search

K
cveMitreCVE-2007-5289
HistoryFeb 24, 2009 - 5:30 p.m.

CVE-2007-5289

2009-02-2417:30:00
CWE-264
mitre
web.nvd.nist.gov
23
hp mercury
quality center
qc
testdirector
remote code execution
ota api
cve-2007-5289

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.197

Percentile

96.4%

HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement “workflow” and decisions about the “capability” of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%\TD_80, and then setting the file’s properties to read-only.

Affected configurations

Nvd
Node
hpmercury_quality_centerRange9.2
OR
hpmercury_quality_centerMatch8.0
OR
hpmercury_quality_centerMatch8.2
OR
hpmercury_quality_centerMatch8.2sp1
OR
hpmercury_quality_centerMatch9.0
OR
hptestdirectorMatch-
VendorProductVersionCPE
hpmercury_quality_center*cpe:2.3:a:hp:mercury_quality_center:*:*:*:*:*:*:*:*
hpmercury_quality_center8.0cpe:2.3:a:hp:mercury_quality_center:8.0:*:*:*:*:*:*:*
hpmercury_quality_center8.2cpe:2.3:a:hp:mercury_quality_center:8.2:*:*:*:*:*:*:*
hpmercury_quality_center8.2cpe:2.3:a:hp:mercury_quality_center:8.2:sp1:*:*:*:*:*:*
hpmercury_quality_center9.0cpe:2.3:a:hp:mercury_quality_center:9.0:*:*:*:*:*:*:*
hptestdirector-cpe:2.3:a:hp:testdirector:-:*:*:*:*:*:*:*

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.197

Percentile

96.4%

Related for CVE-2007-5289