File Upload Vulnerability in HP Operations Manager on Windows
CVE-2009-3843
Currently unrated
Summary
HP Operations Manager 8.10 for Windows is susceptible to a file upload vulnerability due to the presence of a 'hidden account' in the XML file that configures Tomcat users. This flaw enables remote attackers to exploit the org.apache.catalina.manager.HTMLManagerServlet class for unrestricted file upload attacks, potentially leading to the execution of arbitrary code on the affected server.
References
EPSS Score
86% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved