Synopsis
The remote HP-UX host is missing a security-related patch.
Description
s700_800 11.X OV NNM6.4x/ET2.0x Intermediate Patch 17 :
The remote HP-UX host is affected by multiple vulnerabilities :
- Potential vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM) running Apache.
These vulnerabilities could be exploited remotely resulting in cross site scripting (XSS), Denial of Service (DoS), or execution of arbitrary code.
(HPSBMA02328 SSRT071293)
- A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). This vulnerability could be exploited remotely by an unauthorized user to execute arbitrary code with the permissions of the NNM server. (HPSBMA02281 SSRT061261)
- A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM) running Shared Trace Service. The vulnerability could be remotely exploited to execute arbitrary code. (HPSBMA02242 SSRT061260)
- A potential security vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to create a Denial of Service (DoS). (HPSBMA02307 SSRT071420)
- A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). This vulnerability could by exploited remotely to allow cross site scripting (XSS). (HPSBMA02283 SSRT071319)
Solution
Install patch PHSS_37141 or subsequent.
Plugin Details
File Name: hpux_PHSS_37141.nasl
Supported Sensors: Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vulnerability Information
CPE: cpe:/o:hp:hp-ux
Required KB Items: Host/local_checks_enabled, Host/HP-UX/version, Host/HP-UX/swlist
Exploit Ease: Exploits are available
Patch Publication Date: 11/7/2007
Vulnerability Publication Date: 12/5/2005
Exploitable With
Core Impact
Metasploit (HP OpenView Network Node Manager OpenView5.exe CGI Buffer Overflow)
Reference Information
CVE: CVE-2005-3352, CVE-2005-3357, CVE-2006-3747, CVE-2007-3872, CVE-2007-6204, CVE-2007-6343, CVE-2008-0212
BID: 15834, 16152, 19204
CWE: 119, 189, 399, 79
HP: SSRT061260, SSRT061261, SSRT071293, SSRT071319, SSRT071420, emr_na-c01112038, emr_na-c01188923, emr_na-c01218087, emr_na-c01321117, emr_na-c01428449
IAVT: 2007-T-0033-S
TRA: TRA-2007-09