HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: hp
Published:
Updated: 2024-08-07T06:38:30.345Z
Reserved: 2009-11-02T00:00:00
Link: CVE-2009-3843

No data.

Status : Modified
Published: 2009-11-24T00:30:00.420
Modified: 2024-11-21T01:08:18.653
Link: CVE-2009-3843

No data.