← All CVEs

CVE-2011-0276

high · 10

HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.

10
CVSS
82.4%
EPSS (exploit prob.)
100th
EPSS percentile
2011-02-02
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
hpopenview_performance_insight5.2
hpopenview_performance_insight5.3
hpopenview_performance_insight5.4
hpopenview_performance_insight5.31
hpopenview_performance_insight5.41

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-0276