File Upload Vulnerability in HP Operations Manager on Windows
CVE-2009-3843

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
24 November 2009

Summary

HP Operations Manager 8.10 for Windows is susceptible to a file upload vulnerability due to the presence of a 'hidden account' in the XML file that configures Tomcat users. This flaw enables remote attackers to exploit the org.apache.catalina.manager.HTMLManagerServlet class for unrestricted file upload attacks, potentially leading to the execution of arbitrary code on the affected server.

References

EPSS Score

86% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.