T-289: HP StorageWorks Products Remote Management Interface Privilege Escalation Vulnerability
TECHNICAL BULLETIN
TECHNICAL BULLETINPROBLEM: | HP StorageWorks Products Remote Management Interface Privilege Escalation Vulnerability |
PLATFORM: | HP StorageWorks MSL8096 Tape Library firmware 8.90 |
ABSTRACT: | HP StorageWorks products are prone to a privilege-escalation vulnerability in the Remote Management Interface. |
Discussion:
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 1
Then if he changes the RMU_LEVEL (Remote Manager User Level parameter to 2, and then he is an administrator.
Solution:
Install the following patches
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 10
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 11
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 12
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 13
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 14
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 15
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 16
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 17
DOE-CIRC services are available to DOE, DOE Contractors, and the NIH. DOE-CIRC can be contacted at:
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 18
Attacker, once logged in as a regular user, only has to modify his cookie for the webpage that is like: RMU_LEVEL 19
0
References
- ^ Privacy and Legal Notice (www.energy.gov)
- ^ This e-mail address is being protected from spambots. You need JavaScript enabled to view it (circ.jc3.doe.gov)
- ^ http://www.doecirc.energy.gov (www.doecirc.energy.gov)
Authors: JC3-CIRC