|
|
|
|
| |
Credit:
The original article can be found at: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02548231
|
| |
Vulnerable Systems:
* HP Systems Insight Manager (SIM) for HP-UX prior to September 2010 Hotfix
* HP Systems Insight Manager (SIM) for Linux v6.0 prior to September 2010 Hotfix
* HP Systems Insight Manager (SIM) for HP-UX prior to September 2010 Hotfix
* HP Systems Insight Manager (SIM) for Linux v6.1 prior to September 2010 Hotfix
* HP Systems Insight Manager (SIM) for Windows v6.0 prior to September 2010 Hotfix
* HP Systems Insight Manager (SIM) for Windows v6.0 prior to v6.0 Update 2
* HP Systems Insight Manager (SIM) for Windows v6.1 prior to September 2010 Hotfix
* HP Systems Insight Manager (SIM) for Windows v6.1 prior to v6.1 Update 2
The vulnerability could be exploited remotely to download arbitrary files.
Patch Availability:
HP has provided the following hotfixes to resolve the vulnerability for HP-UX, Linux, and Windows
HP-UX, HP SIM v6.0 September 2010 Hotfix
http://h18013.www1.hp.com/products/servers/management/hpsim/dl_hpux60.html#hotfix
HP-UX, HP SIM v6.1 September 2010 Hotfix
http://h18013.www1.hp.com/products/servers/management/hpsim/dl_hpux.html#hotfix
Linux, HP SIM v6.0 September 2010 Hotfix
http://h18013.www1.hp.com/products/servers/management/hpsim/dl_linux60.html#Update
Linux, HP SIM v6.1 September 2010 Hotfix
http://h18013.www1.hp.com/products/servers/management/hpsim/dl_linux61.html#hotfix
Windows, HP SIM v6.0 September 2010 Hotfix
http://h18013.www1.hp.com/products/servers/management/hpsim/dl_windows60.html#hotfix
Windows, HP SIM v6.1 September 2010 Hotfix
http://h18013.www1.hp.com/products/servers/management/hpsim/dl_windows61.html#hotfix
For Windows there are updates available on DVD images; available for download here:
http://h18013.www1.hp.com/products/servers/management/fpdownload.html
CVE Information:
CVE-2010-3286
Disclosure Timeline:
2010-10-13 Initial release
2010-10-13 Last Updated
|
|
|
|
|