Vulnerability Name:

CVE-2008-4412 (CCN-45916)

Assigned:2008-10-15
Published:2008-10-15
Updated:2017-08-08
Summary:Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS v3 Severity:6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-noinfo
CWE-200
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2008-4412

Source: CCN
Type: HP Security Bulletin HPSBMA02378 SSRT080035 rev.2
HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Unauthorized Access to Data

Source: HP
Type: UNKNOWN
SSRT080035

Source: CCN
Type: SA32287
HP Systems Insight Manager Unspecified Unauthorised Access

Source: SECUNIA
Type: Vendor Advisory
32287

Source: CCN
Type: SECTRACK ID: 1021064
HP Systems Insight Manager Lets Remote Users Access Data

Source: CCN
Type: OSVDB ID: 49190
HP Systems Insight Manager Unspecified Remote Information Disclosure

Source: BID
Type: UNKNOWN
31777

Source: CCN
Type: BID-31777
Hewlett-Packard Systems Insight Manager Unspecified Unauthorized Access Vulnerability

Source: SECTRACK
Type: UNKNOWN
1021064

Source: VUPEN
Type: UNKNOWN
ADV-2008-2836

Source: XF
Type: UNKNOWN
hp-sim-unspecified-security-bypass(45916)

Source: XF
Type: UNKNOWN
hp-sim-unspecified-security-bypass(45916)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:hp:systems_insight_manager:*:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.1:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:sp2:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp2:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp3:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp4:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp5:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.1:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:*:update_1:*:*:*:*:*:* (Version <= 5.2)

  • Configuration CCN 1:
  • cpe:/a:hp:systems_insight_manager:5.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    hp systems insight manager * sp1
    hp systems insight manager 4.0
    hp systems insight manager 4.0 sp1
    hp systems insight manager 4.1
    hp systems insight manager 4.1 sp1
    hp systems insight manager 4.2
    hp systems insight manager 4.2 sp1
    hp systems insight manager 4.2 sp2
    hp systems insight manager 5.0
    hp systems insight manager 5.0 sp1
    hp systems insight manager 5.0 sp2
    hp systems insight manager 5.0 sp3
    hp systems insight manager 5.0 sp4
    hp systems insight manager 5.0 sp5
    hp systems insight manager 5.1
    hp systems insight manager 5.2
    hp systems insight manager * update_1
    hp systems insight manager 5.2