| Vulnerability Name: | CVE-2008-4559 (CCN-48588) | ||||||||
| Assigned: | 2008-10-14 | ||||||||
| Published: | 2009-02-06 | ||||||||
| Updated: | 2019-10-09 | ||||||||
| Summary: | HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via shell metacharacters in argument fields to the (1) webappmon.exe or (2) OpenView5.exe CGI program. Note: this issue may be partially covered by CVE-2009-0205. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-20 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-4559 Source: CCN Type: HP Security Bulletin HPSBMA02406 SSRT080100 rev.1 HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code Source: HP Type: UNKNOWN SSRT080100 Source: IDEFENSE Type: Patch 20090206 HP Network Node Manager Multiple Command Injection Vulnerabilities Source: CCN Type: BID-33666 HP OpenView Network Node Manager Multiple Remote Command Execution Vulnerabilities Source: XF Type: UNKNOWN hp-ovnnm-webappmon-command-execution(48588) Source: CCN Type: iDefense Public Advisory: 02.06.09 HP Network Node Manager Multiple Command Injection Vulnerabilities | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||