CVE-2010-0447

HP Openview Performance Insight < 5.4 - Authentication Bypass

Title source: rule

Description

The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.

Scores

EPSS 0.0620
EPSS Percentile 90.7%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

hp/openview_performance_insight < 5.4

Timeline

Published Mar 10, 2010
Tracked Since Feb 18, 2026