Kod programskog paketa HP Business Availability Center uočen je sigurnosni propust koji zlonamjernim korisnicima omogućuje pokretanje napada uskraćivanja usluge.
Paket:
HP Business Availability Center 7.x
Operacijski sustavi:
Microsoft Windows Server 2003, Sun Solaris 9, Sun Solaris 10
Kritičnost:
3.4
Problem:
nepoznat
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2010-4476
Izvorni ID preporuke:
HPSBMU02690
Izvor:
Hewlett Packard
Problem:
Podaci o uzroku sigurnosnog propusta nisu dostupni.
Posljedica:
Udaljeni napadači mogu iskoristiti uočen propust za pokretanje napada uskraćivanja usluge.
Rješenje:
Korisnicima se savjetuje primjena objavljenih rješenja koja uklanjaju uočen propust te detaljnije čitanje izvorne preporuke.
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c02906075
Version: 1
HPSBMU02690 SSRT100569 rev.1 - HP Business Availability Center (BAC) Running on Solaris and Windows, Remote Denial of Service (DoS)
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.
Release Date: 2011-07-07
Last Updated: 2011-07-07
Potential Security Impact: Remote Denial of Service (DoS)
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
A potential security vulnerability has been identified with HP Business Availability Center (BAC) running on Solaris and Windows. The vulnerability can be remotely exploited to create a Denial of Service (DoS).
References: CVE-2010-4476
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
Business Availability Center (BAC) v7.55 running on Solaris and Windows
BACKGROUND
For a PGP signed version of this security bulletin please write to: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
CVSS 2.0 Base Metrics
Reference
Base Vector
Base Score
CVE-2010-4476
AV:N/AC:L/Au:N/C:N/I:N/A:P)
5.0
Information on CVSS is documented in HP Customer Notice: HPSN-2008-002
RESOLUTION
HP has made patches available to resolve the vulnerability. The patches are available here: http://support.openview.hp.com/selfsolve/patches
Product
Patch
BAC v7.55 for Solaris
BAC_00732
BAC v7.55 for Windows
BAC_00731
HISTORY
Version:1 (rev.1) - 7 July 2011 Initial release
Posljednje sigurnosne preporuke