HP Systems Insight Manager < 7.4 Multiple Vulnerabilities

Medium Nessus Plugin ID 78079


The remote Windows host contains software that is affected by multiple vulnerabilities.


The version of HP Systems Insight Manager installed on the remote Windows host is affected by the following vulnerabilities :

- An unspecified vulnerability exists that allows a remote authenticated attacker to gain limited elevated privileges. (CVE-2014-2643)

- A vulnerability exists that allows reflected cross-site scripting attacks, due to the improper validation of user-supplied input before it is returned to the users.
Using a specially crafted request, a remote attacker can execute arbitrary script code within a user's browser.

- An unspecified flaw exists that allows a remote attacker to conduct a clickjacking attack. (CVE-2014-2645)


Upgrade to HP Systems Insight Manager 7.4 or later. A hotfix has also been made available for HP Systems Insight Manager 7.2.

See Also




Plugin Details

Severity: Medium

ID: 78079

File Name: hp_systems_insight_manager_74_multiple_vulns.nasl

Version: $Revision: 1.5 $

Type: local

Agent: windows

Family: Windows

Published: 2014/10/07

Modified: 2016/12/21

Dependencies: 59683

Risk Information

Risk Factor: Medium


Base Score: 4.9

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:hp:systems_insight_manager

Required KB Items: installed_sw/HP Systems Insight Manager

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2014/10/02

Vulnerability Publication Date: 2012/10/02

Reference Information

CVE: CVE-2014-2643, CVE-2014-2644, CVE-2014-2645

BID: 70223, 70224, 70225

OSVDB: 112679, 112680, 112681

HP: emr_na-c04468121, HPSBMU03118, SSRT101715

CWE: 20, 74, 79, 442, 629, 711, 712, 722, 725, 750, 751, 800, 801, 809, 811, 864, 900, 928, 931, 990