10
CVE-2010-0447
- EPSS 6.2%
- Veröffentlicht 10.03.2010 22:30:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle hp-security-alert@hp.com
- CVE-Watchlists
- Unerledigt
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Openview Performance Insight Version <= 5.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.2% | 0.905 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.