Check Point Reference: | CPAI-2014-1828 |
Date Published: | 22 Oct 2014 |
Severity: | Critical |
Last Updated: | Wednesday 22 October, 2014 |
Source: | HP |
Industry Reference: | CVE-2014-2626 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | HP Network Virtualization prior to v8.61 Patch 1 |
Vulnerability Description | A directory traversal vulnerability exists in HP Network Virtualization software. The vulnerability is due to insufficient input validation of user parameters passed to "toServerObject" method. A remote, unauthenticated attacker could exploit this vulnerability by sending crafted HTTP requests to the vulnerable service. In the event of a successful attack, arbitrary files can be created on the server, leading to arbitrary code execution with SYSTEM privileges. |
SmartView Tracker will log the following entries:
Attack Name: HP Products Protection Violation.
Attack Information: HP Network Virtualization toServerObject Directory Traversal