Lucene search

K
zdiStephen Fewer of Harmony Security (www.harmonysecurity.com)ZDI-09-085
HistoryNov 20, 2009 - 12:00 a.m.

Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability

2009-11-2000:00:00
Stephen Fewer of Harmony Security (www.harmonysecurity.com)
www.zerodayinitiative.com
35

0.887 High

EPSS

Percentile

98.7%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard Operations Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists due to a hidden account present within the Tomcat users XML file. Using this account a malicious user can access the org.apache.catalina.manager.HTMLManagerServlet class. This is defined within the catalina-manager.jar file installed with the product. This servlet allows a remote user to upload a file via a POST request to /manager/html/upload. If an attacker uploads malicious content it can then be accessed and executed on the server which leads to arbitrary code execution under the context of the SYSTEM user.