Arbitrary Code Execution Risk in HP Mercury Quality Center and TestDirector
CVE-2007-5289
Currently unrated
What is CVE-2007-5289?
HP Mercury Quality Center versions 9.2 and earlier, along with TestDirector, contain a vulnerability that exploits the reliance on cached client-side scripts to manage user workflows and access capabilities. By leveraging the Open Test Architecture (OTA) API, an attacker can manipulate specific files including common.tds, defects.tds, manrun.tds, req.tds, testlab.tds, and testplan.tds located in the temporary directory. Setting these files to read-only can facilitate unauthorized remote code execution, posing significant risks to system integrity and data security.