Vulnerabilities > CVE-2009-3099 - Remote Security vulnerability in HP Operations Manager 8.1

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
microsoft
hp
critical
nessus
exploit available

Summary

Unspecified vulnerability in HP OpenView Operations Manager 8.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a "Remote exploit," as demonstrated by a certain module in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2007-3872. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

Vulnerable Configurations

Part Description Count
OS
Microsoft
1
Application
Hp
1

Exploit-Db

descriptionHP Operations Manager Default Manager 8.1 Account Remote Security Vulnerability. CVE-2009-3099. Remote exploits for multiple platform
idEDB-ID:33210
last seen2016-02-03
modified2009-09-03
published2009-09-03
reporterIntevydis
sourcehttps://www.exploit-db.com/download/33210/
titleHP Operations Manager Default Manager 8.1 Account Remote Security Vulnerability

Nessus

NASL familyWeb Servers
NASL idTOMCAT_MANAGER_COMMON_CREDS.NASL
descriptionNessus was able to gain access to the Manager web application for the remote Tomcat server using a known set of credentials. A remote attacker can exploit this issue to install a malicious application on the affected server and run arbitrary code with Tomcat
last seen2020-06-01
modified2020-06-02
plugin id34970
published2008-11-26
reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/34970
titleApache Tomcat Manager Common Administrative Credentials