Sponsored Content
Special Forums Cybersecurity Security Advisories (RSS) S-266: HP OpenView Network Node Manager (OV NNM) Running Apache Post 302186628 by Linux Bot on Thursday 17th of April 2008 03:30:04 PM
Old 04-17-2008
S-266: HP OpenView Network Node Manager (OV NNM) Running Apache

Potential vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM) running Apache. These vulnerabilities could be exploited remotely resulting in cross site scripting (XSS), Denial of Service (DoS), or execution of arbitrary code. The risk is MEDIUM. These vulnerabilities could be exploited remotely resulting in cross site scripting (XSS), Denial of Service (DoS), or execution of arbitrary code.


More...
 

7 More Discussions You Might Find Interesting

1. AIX

AIX and HP Network Node Manager

We are using hp's network node manager and would like to monitor quite a few of our aix boxes. It appears that nnm does not have AIX mibs by default. Does anyone know where i can find mibs for aix to load into nnm? Thanks (0 Replies)
Discussion started by: zuessh
0 Replies

2. UNIX for Dummies Questions & Answers

Get Network and Node details

which unix cmd will give the following result... Node Name Task Name ID Status Network NUTTS CTP_E 1000 In Service X25/OFF TCP/ON MUSKET CTP_E 2011 Unreachable X25/OFF TCP/OFF ... (0 Replies)
Discussion started by: rahulrathod
0 Replies

3. Solaris

No network cable But Network interface is UP and Running

I've one Netra 240 After changing main board and system configuration card reader, Network is not accessible any more, Network interfaces are always UP and Running even when there is no cable connected to Network interfaces. I tried to restart and plumb/unplumb with no luck. ifconfig -a... (7 Replies)
Discussion started by: samer.odeh
7 Replies

4. Red Hat

Problem in RedHat Cluster Node while network Failure or in Hang mode

Hi, We are having many RedHat linux Server with Cluster facility for availability of service like HTTPD / MySQL. We face some issue while some issue related to power disturbance / fluctuation or Network failure. There is two Cluster Node configured in... (0 Replies)
Discussion started by: hirenkmistry
0 Replies

5. Shell Programming and Scripting

Running commands in remote node as root user

Platform :Oracle Linux 6.4 We are trying to automate the SAN level cloning from production RAC DB cluster to test. From a shell script, I would like to run the below command Step1,2 and 3 from Node1 in a sequential order as root user . How can I do this ? passwordless for root user is not... (2 Replies)
Discussion started by: kraljic
2 Replies

6. AIX

How to check if HACMP is running on AIX node?

Hello AIX experts, I have few queries and appreciate if you could help me with them. 1. How to check if HACMP (or any other AIX OS cluster) is installed 2. How to check if HACMP (or any other AIX OS cluster) is running 3. how to check which Oracle DB instance is running on it 4. how to... (1 Reply)
Discussion started by: prvnrk
1 Replies

7. Red Hat

Process not running: /opt/java15/jdk/bin/java -classpath /opt/apache/apache-ant-1.7.0-mod/lib/ant-la

Have no idea on what the below error message is: Process not running: /opt/java15/jdk/bin/java -classpath /opt/apache/apache-ant-1.7.0-mod/lib/ant-launcher.jar org.apache.tools.ant.launch.Launcher -buildfile build.xml dist. Any help? (3 Replies)
Discussion started by: gull05
3 Replies
PKG_INSTALL.CONF(5)					      BSD File Formats Manual					       PKG_INSTALL.CONF(5)

NAME
pkg_install.conf -- configuration file for package installation tools DESCRIPTION
The file pkg_install.conf contains system defaults for the package installation tools as a list of variable-value pairs. Each line has the format VARIABLE=VALUE. If the value consists of more than one line, each line is prefixed with VARIABLE=. The current value of a variable can be checked by running pkg_admin config-var VARIABLE Some variables are overriden by environmental variables of the same name. Those are marked by (*). The following variables are supported: ACCEPTABLE_LICENSES Space-separated list of licenses packages are allowed to carry. License names are case-sensitive. ACTIVE_FTP Force the use of active FTP. CACHE_INDEX Cache directory listenings in memory. This avoids retransfers of the large directory index for HTTP and is enabled by default. CERTIFICATE_ANCHOR_PKGS Path to the file containing the certificates used for validating binary packages. A package is trusted when a certificate chain ends in one of the certificates contained in this file. The certificates must be PEM-encoded. CERTIFICATE_ANCHOR_PKGVULN Analogous to CERTIFICATE_ANCHOR_PKGS. The pkg-vulnerabilities is trusted when a certificate chain ends in one of the certificates contained in this file. CERTIFICATE_CHAIN Path to a file containing additional certificates that can be used for completing certificate chains when validating binary packages or pkg-vulnerabilities files. CHECK_LICENSE Check the license conditions of packages before installing them. Supported values are: no The check is not performed. yes The check is performed if the package has license conditions set. always Passing the license check is required. Missing license conditions are considered an error. CHECK_END_OF_FILE During vulnerability checks, consider packages that have reached end-of-life as vulnerable. This option is enabled by default. CHECK_VULNERABILITIES Check for vulnerabilities when installing packages. Supported values are: never No check is performed. always Passing the vulnerability check is required. A missing pkg-vulnerabilities file is considered an error. interactive The user is always asked to confirm installation of vulnerable packages. CONFIG_CACHE_CONNECTIONS Limit the global connection cache to this value. For FTP this is the number of sessions without active command. For HTTP this is the number of connections open with keep-alive. CONFIG_CACHE_CONNECTIONS_HOST Like CONFIG_CACHE_CONNECTIONS, but limit the number of connections to the host as well. See fetch(3) for further details DEFAULT_ACCEPTABLE_LICENSES Space-separated list of common Free and Open Source licenses packages are allowed to carry. The default value contains all OSI approved licenses in pkgsrc on the date pkg_install was released. License names are case-sensitive. GPG Path to gpg(1), which can be used to verify the signature in the pkg-vulnerabilities file when running pkg_admin check-pkg-vulnerabilities -s or pkg_admin fetch-pkg-vulnerabilities -s It can also be used to verify and sign binary packages. GPG_KEYRING_PKGVULN Non-default keyring to use for verifying GPG signatures of pkg-vulnerabilities. GPG_KEYRING_SIGN Non-default keyring to use for signing packages with GPG. GPG_KEYRING_VERIFY Non-default keyring to use for verifying GPG signature of packages. GPG_SIGN_AS User-id to use for signing packages. IGNORE_PROXY Use direct connections and ignore FTP_PROXY and HTTP_PROXY. IGNORE_URL One line per advisory which should be ignored when running pkg_admin audit The URL from the pkg-vulnerabilities file should be used as value. PKG_DBDIR (*) Location of the packages database. This option is always overriden by the argument of the -K option. PKG_PATH (*) Search path for packages. The entries are separated by semicolon. Each entry specifies a directory or URL to search for packages. PKG_REFCOUNT_DBDIR (*) Location of the package reference counts database directory. The default value is ${PKG_DBDIR}.refcount. PKGVULNDIR Directory name in which the pkg-vulnerabilities file resides. Default is ${PKG_DBDIR}. PKGVULNURL URL which is used for updating the local pkg-vulnerabilities file when running pkg_admin fetch-pkg-vulnerabilities The default location is ftp.NetBSD.org using HTTP. Note: Usually, only the compression type should be changed. Currently supported are uncompressed files and files compressed by bzip2(1) (.bz2) or gzip(1) (.gz). VERBOSE_NETIO Log details of network IO to stderr. VERIFIED_INSTALLATION Set trust level used when installation. Supported values are: never No signature checks are performed. always A valid signature is required. If the binary package can not be verified, the installation is terminated trusted A valid signature is required. If the binary package can not be verified, the user is asked interactively. interactive The user is always asked interactively when installing a package. FILES
/etc/pkg_install.conf Default location for the file described in this manual page. SEE ALSO
pkg_add(1), pkg_admin(1) pkg_create(1), pkg_delete(1), pkg_info(1) BSD
November 13, 2010 BSD
All times are GMT -4. The time now is 08:15 PM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy