Overview
A vulnerability in HP OpenView Storage Data Protector may allow an attacker to issue arbitrary commands on an affected system.
Description
HP Openview HP Openview is a range of products, distributed and developed by Hewlett Packard, that are used for enterprise system and network monitoring.  | 
Impact
An remote, unauthenticated attacker may be able execute arbitrary commands on the backup agents with system privileges.  | 
Solution
Apply a patch from the vendor  | 
Restrict access  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00742778&jumpid=reg_R1002_USEN
 - http://itrc.hp.com/service/cki/docDisplay.do?docId=c00742778
 - http://www.uniras.gov.uk/niscc/docs/re-20060811-00547.pdf?lang=en
 - http://secunia.com/advisories/21485/
 - http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00663793/c00663793.pdf
 
Acknowledgements
This vulnerability was originally reported by NISCC.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | CVE-2006-4201 | 
| Severity Metric: | 0.94 | 
| Date Public: | 2006-08-14 | 
| Date First Published: | 2006-08-23 | 
| Date Last Updated: | 2007-01-12 21:39 UTC | 
| Document Revision: | 28 |