HP Plugs Critical Security Holes in OpenView Network Management Technology

Écrit par
Brian Prince
Brian Prince
Published: Mar 24, 2009
Updated: Feb 2, 2021
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Core Security Technologies has issued an advisory for multiple vulnerabilities affecting HP’s popular OpenView systems and network management software.

An engineer from CoreLabs, the company’s research arm, uncovered three vulnerabilities in HP OpenView NNM (Network Node Manager) that can be exploited remotely via buffer overflows to compromise mission-critical servers. Though two of the vulnerabilities are brand new, the third is a stack-based bug found on CGI parameter OvOSLocale that HP had previously issued a patch for but was still exploitable.

According to CoreLabs, attackers can leverage the vulnerabilities by sending specially crafted HTTP requests to HP OpenView’s Web server component, allowing them to execute arbitrary code on the target system. HP has issued fixes for all three vulnerabilities in response to CoreLabs’ findings.

“While remote network management technologies offer substantial value in terms of allowing organizations to maintain constant vigilance and control over their networks, the flipside is that attackers can potentially use available vulnerabilities in these systems to wreak havoc on internal infrastructure,” said Ivan Arce, CTO of Core Security Technologies, in a statement. “It is vitally important for remote systems management solution providers to minimize these easily exploitable security flaws that can allow for remote system compromise.”

HP OpenView NNM is a widely used remote network management technology that allows network managers to monitor their physical networks, virtual network services and the relationships between those assets.

While examining a set of previously disclosed vulnerabilities affecting the product, a researcher at CoreLabs uncovered that OpenView NMM versions 7.51 and 7.53 harbored two previously unknown flaws, and that a patch for the third security issued could be circumvented.

The flaws also affect Version 7.01. The HP support document addressing these issues can be found here.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.