VendorsHPopenview_performance_insightall versions
Vulnerabilities

HP Openview Performance Insight

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2011-0276
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.
Published 2011-02-02 · Modified
10.01 PoCEPSS 0.824
CVE-2010-0447
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.
Published 2010-03-10 · Modified
10.0EPSS 0.053
CVE-2011-2407
Unspecified vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to obtain access via unknown vectors.
Published 2011-08-11 · Modified
6.4EPSS 0.025
CVE-2011-2410
Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2011-08-19 · Modified
4.3EPSS 0.015
CVE-2011-2406
Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2011-08-11 · Modified
3.5EPSS 0.009