| PROBLEM: | HP JetAdmin prior to 7.5 possibly others, has several security vulnerabilities that can be exploited by remote attacker. 1) A specially-crafted HTTP request can disclose the source content of certain file types. (ISS #15980) 2) The file framework.ini can be used to obtain sensitive information. (ISS# 15981 & ISS #15982) 3) A weak encryption sceme is used to protect the administration password and username. (ISS #15984) 4) The weak encryption scheme allows captured packets to be used later in a replay attack. (ISS# 15985) 5) Password validation can be bypassed to use services that are reserved to administrative users. (ISS# 15986) 6) Arbitrary data can be written to the file cache.ini which has session-specific information. (ISS #15988) 7) Installed programs can be executed, possibly with SYSTSM or root privileges. (ISS #15989) |
| PLATFORM: | HP JetAdmin 6.2 and earlier HP JetAdmin 6.5 HP JetAdmin 7.0 Various: Any operating system Any version |
| DAMAGE: | A remote attacker could run a program, possibly with SYSTEM level or root privileges. |
| SOLUTION: | Upgrade to the latest version of HP Web JetAdmin (7.5 or later). |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. A remote attacker can run code with SYSTEM level or root privileges. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/o-136.shtml |
| ORIGINAL BULLETIN: | http://xforce.iss.net/xforce/xfdb/15989 |
| ADDITIONAL LINKS: | Visit HEWLETT PACKARD Subscription Service for: HPSBPI01026 SSRT2397 |
| ISS X-Force Security Alerts |
|
| http://xforce.iss.net/xforce/xfdb/15980 | |
| http://xforce.iss.net/xforce/xfdb/15981 | |
| http://xforce.iss.net/xforce/xfdb/15982 | |
| http://xforce.iss.net/xforce/xfdb/15984 | |
| http://xforce.iss.net/xforce/xfdb/15985 | |
| http://xforce.iss.net/xforce/xfdb/15986 | |
| http://xforce.iss.net/xforce/xfdb/15988 | |
[***** Start of CIAC Note *****] ISS has written notices on several of the vulnerabilities that are addressed by the HP upgrade. The ISS Bulletin referenced below is about executing installed programs. The URLs to the other notices are given in the Additional Links section above. [***** End of CIAC Note *****] Visit ISS X-Force web site directly for their published information. http://xforce.iss.net/xforce/xfdb/15989
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org