Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
HPSBMU02769 SSRT100846 rev.1 - HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Unauthorized Access, Execution of Arbitrary Code, and Other Vulnerabilities
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  1 message - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Security Alert  
View profile  
 More options Apr 30 2012, 1:37 pm
Newsgroups: comp.sys.hp.hpux, comp.security.unix, comp.security.misc
Followup-To: comp.sys.hp.hpux
From: security-al...@hp.com (Security Alert)
Date: Mon, 30 Apr 2012 17:37:32 +0000 (UTC)
Local: Mon, Apr 30 2012 1:37 pm
Subject: HPSBMU02769 SSRT100846 rev.1 - HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Unauthorized Access, Execution of Arbitrary Code, and Other Vulnerabilities
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c03298151Version: 1
HPSBMU02769 SSRT100846 rev.1 - HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Unauthorized Access, Execution of Arbitrary Code, and Other Vulnerabilities

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2012-04-30Last Updated: 2012-04-30
________________________________________
Potential Security Impact: Remote unauthorized access, execution of arbitrary code, and other vulnerabilities
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified with HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows. The vulnerabilities could be exploited remotely resulting in unauthorized access, execution of arbitrary code, information disclosure , cross site request forgery (CSRF), URL redirection, authentication bypass, and Denial of Service (DoS).
References: CVE-2010-2227, CVE-2009-3555, CVE-2011-2445, CVE-2011-2450, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, CVE-2011-2456, CVE-2011-2457, CVE-2011-2458, CVE-2011-2459, CVE-2011-2460, CVE-2011-2426, CVE-2011-2444, CVE-2011-2427, CVE-2011-2428, CVE-2011-2429, CVE-2011-2430, CVE-2011-2130, CVE-2011-2134, CVE-2011-2135, CVE-2011-2136, CVE-2011-2137, CVE-2011-2138, CVE-2011-2139, CVE-2011-2140, CVE-2011-2414, CVE-2011-2415, CVE-2011-2416, CVE-2011-2417, CVE-2011-2425, CVE-2011-0611, CVE-2011-2092, CVE-2011-2093, CVE-2011-2461, CVE-2011-3556, CVE-2011-3557, CVE-2011-3558, CVE-2011-0786, CVE-2011-0788, CVE-2011-0802, CVE-2011-0814, CVE-2011-0815, CVE-2011-0817, CVE-2011-0862, CVE-2011-0863, CVE-2011-0864, CVE-2011-0865, CVE-2011-0866, CVE-2011-0867, CVE-2011-0868, CVE-2011-0869, CVE-2011-0871, CVE-2011-0872, CVE-2011-0873, CVE-2010-4476, CVE-2010-4470, CVE-2012-1994 (unauthorized access), CVE-2012-1995 ( information disclosure), CVE-2012-1996 (CSRF), CVE-2012-1997 (privilege elevation), CVE-2012-1998 (URL redirection), CVE-2012-1999 (authentication bypass), SSRT100093, SSRT090028, SSRT100110, SSRT100373, SSRT100426, SSRT100514, SSRT100562, SSRT100639, SSRT100702, SSRT100819
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP System Insight Manager prior to v7.0
BACKGROUND

CVSS 2.0 Base Metrics
CVSS 2.0 Base Metrics
================================================================
  Reference                 Base Vector               Base Score
CVE-2009-3555       (AV:N/AC:M/Au:N/C:N/I:P/A:P)          5.8
CVE-2010-2227       (AV:N/AC:L/Au:N/C:P/I:N/A:P)          6.4
CVE-2010-4470       (AV:N/AC:L/Au:N/C:N/I:N/A:P)          5.0
CVE-2010-4476       (AV:N/AC:L/Au:N/C:N/I:N/A:P)          5.0
CVE-2011-0611       (AV:N/AC:M/Au:N/C:C/I:C/A:C)          9.3
CVE-2011-0786       (AV:N/AC:H/Au:N/C:C/I:C/A:C)          7.6
CVE-2011-0788       (AV:N/AC:H/Au:N/C:C/I:C/A:C)          7.6
CVE-2011-0802       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-0814       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-0815       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-0817       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-0862       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-0863       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-0864       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-0865       (AV:N/AC:H/Au:N/C:N/I:P/A:N)          2.6
CVE-2011-0866       (AV:N/AC:H/Au:N/C:C/I:C/A:C)          7.6
CVE-2011-0867       (AV:N/AC:L/Au:N/C:P/I:N/A:N)          5.0
CVE-2011-0868       (AV:N/AC:L/Au:N/C:P/I:N/A:N)          5.0
CVE-2011-0869       (AV:N/AC:L/Au:N/C:P/I:N/A:N)          5.0
CVE-2011-0871       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-0872       (AV:N/AC:L/Au:N/C:N/I:N/A:P)          5.0
CVE-2011-0873       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2092       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2093       (AV:N/AC:L/Au:N/C:N/I:N/A:P)          5.0
CVE-2011-2130       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2134       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2135       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2136       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2137       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2138       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2139       (AV:N/AC:L/Au:N/C:P/I:P/A:N)          6.4
CVE-2011-2140       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2414       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2415       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2416       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2417       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2425       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2426       (AV:N/AC:M/Au:N/C:C/I:C/A:C)          9.3
CVE-2011-2427       (AV:N/AC:M/Au:N/C:C/I:C/A:C)          9.3
CVE-2011-2428       (AV:N/AC:M/Au:N/C:C/I:C/A:C)          9.3
CVE-2011-2429       (AV:N/AC:L/Au:N/C:P/I:N/A:N)          5.0
CVE-2011-2430       (AV:N/AC:M/Au:N/C:C/I:C/A:C)          9.3
CVE-2011-2444       (AV:N/AC:M/Au:N/C:N/I:P/A:N)          4.3
CVE-2011-2445       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2450       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2451       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2452       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2453       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2454       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2455       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2456       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2457       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2458       (AV:N/AC:M/Au:N/C:C/I:C/A:C)          9.3
CVE-2011-2459       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2460       (AV:N/AC:L/Au:N/C:C/I:C/A:C)         10.0
CVE-2011-2461       (AV:N/AC:M/Au:N/C:N/I:P/A:N)          4.3
CVE-2011-3556       (AV:N/AC:L/Au:N/C:P/I:P/A:P)          7.5
CVE-2011-3557       (AV:N/AC:M/Au:N/C:P/I:P/A:P)          6.8
CVE-2011-3558       (AV:N/AC:L/Au:N/C:P/I:N/A:N)          5.0
CVE-2012-1994       (AV:A/AC:M/Au:N/C:P/I:C/A:N)          6.4
CVE-2012-1995       (AV:L/AC:L/Au:S/C:P/I:P/A:N)          3.2
CVE-2012-1996       (AV:N/AC:M/Au:N/C:N/I:P/A:N)          4.3
CVE-2012-1997    (AV:N /AC:L /Au:N /C:P /I:P /A:P)        7.5
CVE-2012-1998       (AV:N/AC:M/Au:N/C:P/I:P/A:P)          6.8
CVE-2012-1999       (AV:N/AC:L/Au:S/C:C/I:C/A:N)          8.5
================================================================
               Information on CVSS is documented
              in HP Customer Notice: HPSN-2008-002

RESOLUTION

HP has provided HP System Insight Manager v7.0 (bundled with IM v7.0) for Windows, Linux, and HP-UX to resolve these vulnerabilities. HP System Insight Manager v7.0 is available here:
http://h18013.www1.hp.com/products/servers/management/hpsim/download....
MANUAL ACTIONS: Yes - Update
For HP-UX, install HP SIM v7.0 or subsequent
PRODUCT SPECIFIC INFORMATION
HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see: https://www.hp.com/go/swa
The following text is for use by the HP-UX Software Assistant.
AFFECTED VERSIONS
HP-UX B.11.23
HP-UX B.11.31
=============
SysMgmtServer.MX-CMS
SysMgmtServer.MX-CORE
SysMgmtServer.MX-CORE-ARCH
SysMgmtServer.MX-JBOSS
SysMgmtServer.MX-JRE
SysMgmtServer.MX-PORTAL
SysMgmtServer.MX-REPO
SysMgmtServer.MX-TOOLS
action: install revision C.07.00.00.00.05 or subsequent
END AFFECTED VERSIONS
HISTORY
Version: 1 (rev.1) - 30 April 2012 Initial release
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel.  For other issues about the content of this Security Bulletin, send e-mail to security-al...@hp.com.

Report: To report a potential security vulnerability with any HP supported product, send Email to: security-al...@hp.com

Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Security Bulletin List: A list of HP Security Bulletins, updated periodically, is contained in HP Security Notice HPSN-2011-001: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?doc...

Security Bulletin Archive: A list of recently released Security Bulletins is available here: http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/

Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB.

3C = 3COM
3P = 3rd Party Software
GN = HP General Software
HF = HP Hardware and Firmware
MP = MPE/iX
MU = Multi-Platform Software
NS = NonStop Servers
OV = OpenVMS
PI = Printing and Imaging
PV = ProCurve
ST = Storage Software
TU = Tru64 UNIX
UX = HP-UX

Copyright 2012 Hewlett-Packard Development Company, L.P.
Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAk+erC4ACgkQ4B86/C0qfVkCqwCcDGPZ9YxPF6osycqmai0T0wxH
4V4AnR97bF3LfrNdL0Dvz83mvoigV7tI
=vqR/
-----END PGP SIGNATURE-----

--
Yours truly,
HP S/W Security Team
WTEC Cupertino, California

Return-Path: sec...@cup.hp.com
Reply-to: security-al...@hp.com


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »