Vulnerable Systems:
* HP Power Manager all versions on Linux
* HP Power Manager all versions on Windows
HP Power Manager (HPPM) Constains a potential security vulnerability running on Linux and Windows. The vulnerability could result in a cross site request forgery (CSRF) leading to unauthorized administrative access
Workaround:
HP recommends the following:
Open a browser instance, log on to HPPM, perform needed task, and log off from HPPM
Do not visit untrusted web sites while logged on to HPPM
Use a firewall to limit access to HPPM
In addition accessing HPPM using HTTPS is recommended.