HP released bulletin HPSBMA02535 (SSRT100029 rev.1) to remediate nine vulnerabilities in HP Performance Manager versions 8.10, 8.20, and 8.21 for HP-UX, Linux, Solaris, and Windows. The flaws could enable remote unauthorized access, cross-site scripting, and denial-of-service conditions; CVE-2009-3548 was rated highest, with a CVSS v2 base score of 7.5 and potential impact to confidentiality, integrity, and availability.
HP issued platform-specific updates: HPPM8CPI_00001 for HP-UX IA, HPPM8CPP_00001 for HP-UX PA, HPPM8CPL_00001 for Linux, HPPM8CPS_00001 for Solaris, and HPPM8CPW_00001 for Windows. Related Apache Tomcat advisories also addressed CVE-2009-0580, a FORM-authentication user-enumeration flaw in Tomcat 4.1.x, 5.5.x, and 6.0.x that lets remote attackers identify valid usernames through malformed URL-encoded password input to /j_security_check.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Hewlett-Packard published HPSBMA02535 (SSRT100029 rev.1) addressing nine remote-access, cross-site-scripting, and denial-of-service vulnerabilities in HP Performance Manager 8.10, 8.20, and 8.21. HP released platform-specific patches for HP-UX, Linux, Solaris, and Windows, including fixes for CVE-2009-3548 and the other listed CVEs.
CVE-2009-0580 was published for an Apache Tomcat FORM-authentication flaw that lets remote attackers distinguish valid usernames through malformed URL-encoded passwords sent to /j_security_check. It affects specified Tomcat 4.1.x, 5.5.x, and 6.0.x versions using the affected authentication realms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcemarc.info
Open sourcemandriva.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.