HP Operations Manager i (OMi) 9.1 / 9.2 RCE

high Nessus Plugin ID 74253

Synopsis

The remote host has an operations management application installed that is affected by an unspecified code execution vulnerability.

Description

The HP Operations Manager i (OMi) installed on the remote host is version 9.1 or 9.2. It is, therefore, affected by an unspecified code execution vulnerability that allows an authenticated, remote attacker to execute arbitrary code by leveraging the OMi operator role.

Solution

Apply the vendor-supplied patch.

See Also

http://www.nessus.org/u?87d5d6f0

https://www.securityfocus.com/archive/1/532177/30/0/threaded

Plugin Details

Severity: High

ID: 74253

File Name: hp_ops_manageri_hpsbmu03042.nasl

Version: 1.5

Type: local

Agent: windows

Family: Windows

Published: 5/30/2014

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:hp:operations_manager_i

Required KB Items: SMB/HP Operations Manager i/Version, SMB/HP Operations Manager i/Build, SMB/HP Operations Manager i/Path

Exploit Ease: No known exploits are available

Patch Publication Date: 5/20/2014

Vulnerability Publication Date: 5/20/2014

Reference Information

CVE: CVE-2014-2607

BID: 67570

HP: HPSBMU03042, SSRT101575, emr_na-c04296442

IAVB: 2014-B-0064