Vulnerabilities > CVE-2009-4188 - Credentials Management vulnerability in HP Operations Dashboard

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
hp
CWE-255
critical
exploit available
metasploit

Summary

HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3098.

Vulnerable Configurations

Part Description Count
Application
Hp
1

Common Weakness Enumeration (CWE)

Exploit-Db

  • descriptionHP Operations Dashboard 2.1 Portal Default Manager Account Remote Security Vulnerability. CVE-2009-4188. Remote exploits for multiple platform
    idEDB-ID:33211
    last seen2016-02-03
    modified2009-09-03
    published2009-09-03
    reporterIntevydis
    sourcehttps://www.exploit-db.com/download/33211/
    titleHP Operations Dashboard 2.1 Portal Default Manager Account Remote Security Vulnerability
  • descriptionApache Tomcat Manager Application Deployer Authenticated Code Execution. CVE-2009-3548,CVE-2009-3843,CVE-2009-4188,CVE-2009-4189,CVE-2010-0557,CVE-2010-4094....
    idEDB-ID:16317
    last seen2016-02-01
    modified2010-12-14
    published2010-12-14
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16317/
    titleApache Tomcat Manager Application Deployer Authenticated Code Execution

Metasploit

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/125021/tomcat_mgr_upload.rb.txt
idPACKETSTORM:125021
last seen2016-12-05
published2014-02-01
reporterrangercha
sourcehttps://packetstormsecurity.com/files/125021/Apache-Tomcat-Manager-Code-Execution.html
titleApache Tomcat Manager Code Execution