HP Systems Insight Manager (SIM) CSRF, CSS and Privilege Escalation Vulnerabilities
30 Nov. 2010
Summary
Cross Site Request Forgery, Cross Site Scripting and Privilege Escalation vulnerabilities have been identified in HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows.
Vulnerable Systems:
* HP Systems Insight Manager (SIM) for HP-UX prior to v6.2
* HP Systems Insight Manager (SIM) for Linux prior to v6.2
* HP Systems Insight Manager (SIM) for Windows prior to v6.2
Immune Systems:
* HP Systems Insight Manager (SIM) for HP-UX v6.2
* HP Systems Insight Manager (SIM) for Linux v6.2
* HP Systems Insight Manager (SIM) for Windows v6.2
The vulnerabilities could be exploited remotely resulting in cross site request forgery (CSRF), cross site scripting (XSS), and privilege escalation attacks.