Sploitus

CVE-2009-4189

6 known exploits for CVE-2009-4189

HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3099 and CVE-2009-3843.

Affected products
Hp Operations Manager
Hp Operations Manager
All versions
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
78.5% (100th percentile)
Weakness
CWE-255
NVD status
Modified
Published
2009-12-03
CVE-2009-4189 at NVD
Authoritative description, scoring and affected products

6 known exploits for CVE-2009-4189

Proof-of-concept code and exploit modules indexed by Sploitus