Vulnerability Name:
CVE-2010-2709 (CCN-60880)
Assigned:
2010-08-03
Published:
2010-08-03
Updated:
2017-08-17
Summary:
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie.
CVSS v3 Severity:
10.0 Critical
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
9.3 High
(CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C
)
6.9 Medium
(Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
9.3 High
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C
)
6.9 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Type:
CWE-119
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2010-2709
Source: HP
Type: Patch, Vendor Advisory
SSRT100165
Source: SREASON
Type: UNKNOWN
8150
Source: CCN
Type: SECTRACK ID: 1024274
HP OpenView Network Node Manager Bug Lets Remote Users Execute Arbitrary Code
Source: SECTRACK
Type: UNKNOWN
1024274
Source: CCN
Type: CORE-2010-0608
HP OpenView NNM OvJavaLocale Buffer Overflow Vulnerability
Source: MISC
Type: UNKNOWN
http://www.coresecurity.com/content/hp-nnm-ovjavalocale-buffer-overflow
Source: EXPLOIT-DB
Type: Exploit
14547
Source: CCN
Type: OSVDB ID: 66932
HP OpenView Network Node Manager (OV NNM) webappmon.exe OvJavaLocale Cookie Value Handling Remote Overflow
Source: BID
Type: Patch
42154
Source: CCN
Type: BID-42154
HP OpenView Network Node Manager 'OvJavaLocale' Cookie Value Remote Code Execution Vulnerability
Source: XF
Type: UNKNOWN
hp-ovnnm-ovjavalocale-bo(60880)
Source: XF
Type: UNKNOWN
hp-ovnnm-ovjavalocale-bo(60880)
Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [08-3-2010]
Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [03-23-2011]
Source: CCN
Type: HP Security Bulletin HPSBMA02563 SSRT100165 rev.1
HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
Vulnerable Configuration:
Configuration 1
:
cpe:/a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:hp-ux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:linux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:solaris:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:windows:*:*:*:*:*
Configuration 2
:
cpe:/a:hp:openview_network_node_manager:7.53:*:*:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:hp-ux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:linux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:solaris:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:windows:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:hp:openview_network_node_manager:7.51:-:hp-ux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:linux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:solaris:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:windows:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:hp-ux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:linux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:solaris:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:windows:*:*:*:*:*
Denotes that component is vulnerable
BACK
hp
openview network node manager 7.51
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.53
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -