HP Business Availability Center Running Apache Multiple Vulnerabilities
26 Jul. 2010
Summary
Cross Site Scripting, Cross Site Request Forgery and Denial of Service vulnerabilities were discovered in HP Business Availability Center running Apache on Windows and Solaris.
Vulnerable Systems:
* Business Availability Center v8.01 and earlier on Windows
* Business Availability Center v8.01 and earlier on Solaris
Potential security vulnerabilities have been identified with HP Business Availability Center running Apache. The vulnerabilities could be remotely exploited to allow Cross Site Scripting, Cross Site Request Forgery, and Denial of Service.
Patch Availability:
HP has made the following updated product kit available to resolve the vulnerabilities.
The HP Business Availability Center v8.02 kit is available on the HP Software Support Online portal at: http://support.openview.hp.com/support.jsp .