Release date:
Updated on:
Affected Systems:
HP mistum 11.21
HP SiteScope 11.1x
HP SiteScope 10.1x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65972
CVE (CAN) ID: CVE-2013-6207
HP SiteScope is a non-agent monitoring software that maintains the availability and performance of its distributed IT infrastructure.
The loadFileContents SOAP function of SiteScope 10.1x, 11.1x, and 11.21 has a security vulnerability. After successful exploitation, attackers can execute arbitrary code, download arbitrary files, and reject services.
<* Source: Mike Arnold (Bruk0ut)
Link: http://seclists.org/bugtraq/2014/Mar/27
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
HP
--
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://itrc.hp.com
Http://support.openview.hp.com/