Sploitus

Exploit for HP Universal CMDB Server Axis2 default password

saint Β· 2011-02-22

Exploit Code

MARKDOWN33 lines
## https://sploitus.com/exploit?id=SAINT:F0B63D5C0D1D97A5E4EA97AEC15DBB11
Added: 02/22/2011  
CVE: CVE-2010-0219  
BID: 45625  
OSVDB: 70233  


### Background

HP Universal CMDB Server 9.0 is a modular management system that consists of a rich business-service-oriented data model with built-in discovery of configuration items (CIs) and configuration item dependencies, visualization and mapping of business services, and tracking of configuration changes. 

### Problem

HP UCMDB deploys Axis2 with default credentials which can be used to gain unauthorized access to the web application server. By then uploading a specially crafted axis2 service, an attacker could execute arbitrary commands on the system. 

### Resolution

Change the password for the admin account in the axis2.xml file, which is found in the \hp\UCMDB\UCMDBServer\deploy\axis2\WEB-INF\conf\ folder. 

### References

http://www.securityfocus.com/archive/1/515494   


### Limitations

Exploit works on HP Universal CMDB Server 9.0. 

There may be a delay before the exploit succeeds. 

### Platforms

Windows