search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Hewlett-Packard MPE/ix contains vulnerabitily via architected interface facility

Vulnerability Note VU#895496

Original Release Date: 2001-05-01 | Last Revised: 2001-06-26

Overview

A vulnerability in certain Hewlett-Packard systems allows users to gain unauthorized access to user accounts and databases using the architected interface facility.

Description

HP3000 systems running MPE/iX release 5.5 and newer contain a vulnerability in the architected interface facility that allows users to gain unauthorized access to user accounts and databases. No further details are available. See HP document HPSBMP0103-011.

Impact

The complete impact of this vulnerability is not yet known.

Solution

Apply the patches described in the HP bulletin described above.

Vendor Information

895496
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This document was written by Shawn V. Hernan.

Other Information

CVE IDs: CVE-2001-0608
Date Public: 2001-03-12
Date First Published: 2001-05-01
Date Last Updated: 2001-06-26 02:23 UTC
Document Revision: 4

Sponsored by CISA.