|
HP Oracle for OpenView Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA31113
|
|
|
Release Date:
|
2008-07-16
|
|
Popularity:
|
1,902 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Unknown Security Bypass Exposure of sensitive information Privilege escalation DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | HP Oracle for OpenView (OfO) 8.x HP Oracle for OpenView (OfO) 9.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2007-1359 CVE-2008-1666 CVE-2008-2576 CVE-2008-2577 CVE-2008-2578 CVE-2008-2579 CVE-2008-2580 CVE-2008-2581 CVE-2008-2582 CVE-2008-2583 CVE-2008-2585 CVE-2008-2586 CVE-2008-2587 CVE-2008-2589 CVE-2008-2590 CVE-2008-2591 CVE-2008-2592 CVE-2008-2593 CVE-2008-2594 CVE-2008-2595 CVE-2008-2596 CVE-2008-2597 CVE-2008-2598 CVE-2008-2599 CVE-2008-2600 CVE-2008-2601 CVE-2008-2602 CVE-2008-2603 CVE-2008-2604 CVE-2008-2605 CVE-2008-2606 CVE-2008-2607 CVE-2008-2608 CVE-2008-2609 CVE-2008-2610 CVE-2008-2611 CVE-2008-2612 CVE-2008-2613 CVE-2008-2614 CVE-2008-2615 CVE-2008-2616 CVE-2008-2617 CVE-2008-2618 CVE-2008-2620 CVE-2008-2621 CVE-2008-2622
|
|
Description: HP has acknowledged some vulnerabilities in HP Oracle for Openview (OfO). Some vulnerabilities have unknown impacts while others can be exploited by malicious, local users to gain escalated privileges, by malicious users to cause a DoS (Denial of Service), disclose sensitive information, gain escalated privileges, or compromise a vulnerable system, and by malicious people to bypass certain security restrictions or to cause a DoS.
For more information:
SA31087
The vulnerabilities are reported in versions v8.1.7, v9.1.01, v9.2, v9.2.0, v10g, and v10gR2 running on HP-UX, Tru64 UNIX, Linux, Solaris, and Windows.
Solution: Install the Oracle Critical Patch Update - July 2008.
Original Advisory: HPSBMA02133 SSRT061201 rev.9:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143
Other References: SA31087:
http://secunia.com/advisories/31087/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|