Lucene search

K
cve[email protected]CVE-2008-4560
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2008-4560

2022-10-0316:14:00
CWE-200
web.nvd.nist.gov
37
cve-2008-4560
hp openview
nnm
remote attack
sensitive information
cgi program

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

6 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.2%

HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to obtain sensitive information via (1) a crafted request to the nnmRptConfig.exe CGI program, which reveals the pathname of log directories; or (2) a crafted parameter in a request to the ovlaunch.exe CGI program, which reveals configuration details. NOTE: this issue may be partially covered by CVE-2009-0205.

Affected configurations

NVD
Node
hpopenview_network_node_managerMatch7.0.1hp_ux
OR
hpopenview_network_node_managerMatch7.0.1linux
OR
hpopenview_network_node_managerMatch7.0.1solaris
OR
hpopenview_network_node_managerMatch7.0.1windows
OR
hpopenview_network_node_managerMatch7.51-hp-ux
OR
hpopenview_network_node_managerMatch7.51-linux
OR
hpopenview_network_node_managerMatch7.51-solaris
OR
hpopenview_network_node_managerMatch7.51-windows
OR
hpopenview_network_node_managerMatch7.53-hp-ux
OR
hpopenview_network_node_managerMatch7.53-linux
OR
hpopenview_network_node_managerMatch7.53-solaris
OR
hpopenview_network_node_managerMatch7.53-windows

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

6 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.2%