header-logo
Suggest Exploit
vendor:
OpenView Network Node Manager
by:
SecurityFocus
7.5
CVSS
HIGH
Directory-Traversal and Denial-of-Service
22, 20
CWE
Product Name: OpenView Network Node Manager
Affected Version From: 7.51
Affected Version To: 7.53
Patch Exists: Yes
Related CWE: N/A
CPE: a:hewlett_packard:openview_network_node_manager
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2008

HP OpenView Network Node Manager Multiple Vulnerabilities

HP OpenView Network Node Manager is prone to multiple vulnerabilities affecting the 'ovalarmsrv.exe' and 'ovtopmd.exe' processes. These issues include a directory-traversal issue and multiple denial-of-service issues. Attackers can exploit these issues to access potentially sensitive data on the affected computer or to deny service to legitimate users.

Mitigation:

Upgrade to the latest version of HP OpenView Network Node Manager.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/28745/info

HP OpenView Network Node Manager is prone to multiple vulnerabilities affecting the 'ovalarmsrv.exe' and 'ovtopmd.exe' processes. These issues include a directory-traversal issue and multiple denial-of-service issues.

UPDATE (April 14, 2008): Secunia Research discovered, independently, that the 'OpenView5.exe' process is also prone to the directory-traversal issue; this affects Network Node Manager 7.51. Note that 'ovalarmsrv.exe' may also be named 'OpenView5.exe'.

Attackers can exploit these issues to access potentially sensitive data on the affected computer or to deny service to legitimate users.

HP OpenView Network Node Manager 7.53 is vulnerable; other versions may also be affected.

http://www.example.com/OvCgi/OpenView5.exe?Target=Main&Action=../../../../../../windows/win.ini