Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
HP.com home

Software Security Customer Advisories

» 

Servers

» ProLiant servers
» BladeSystem
» ProLiant DL
(rack-optimized)
» ProLiant ML
(expansion-optimized)
» ProLiant solutions
» Insight Control
» ProLiant storage
» Rack & Power
» Options & Accessories
Related information
» ProLiant Advantage
» Benchmarks
» Technology communications
» SMB Server & Storage Expertise Center
Purchasing
» Buy/Contact HP Worldwide
» Server buying guide
» Let HP customize and integrate with Factory Express
» ProLiant US smart buys
» Special US promotions
» HP Trade-In Program
announcing new products
What's new in IT? HP Virtual IT Center
What's new in IT? HP Virtual IT Center
 
Content starts here

ProLiant management software and other applications sharing a common architecture

Product information

» Recent advisories
» Advisory archive

Recent advisories

» Patch to address SSLv2 rollback issue, plus OpenSSL 0.9.6m update (17 November 2005)
As part of an ongoing commitment to software quality, an issue has been discovered within HP HTTP Server versions 5.0 through 5.96. HP HTTP Server is a component of HP Web Based Management Products for Microsoft Windows NT 4.0, Windows 2000, and Windows 2003.

HP has addressed the following issues in HP HTTP Server version 5.97:
  • Updated to OpenSSL 0.9.6m+ patch for SSL v2 Rollback issue (CAN-2005-2969)
This update is recommended for all systems running HP web-based management software and Microsoft Windows NT 4.0, plus systems running Windows 2000, Windows 2003 and versions of HP web-based management software prior to v7.20 of the HP ProLiant Support Pack, HP SmartStart CD and HP Management CD. See the Table of Affected Software for version details.

You can verify the version of HP HTTP Server by viewing the bottom left corner of the System Management Homepage. For some older versions, you will need to hover over the copyright line. HP strongly recommends that you update your software as soon as possible to remove the vulnerabilities listed above.

Table of affected software Download patch


» Enabling Anonymous Access In HP Web-enabled Management Software Security Vulnerability (SSRT4679) (14 January 2004)
As part of an ongoing commitment to software quality, an issue has been discovered within HP HTTP Server versions 5.0 through 5.95. HP HTTP Server is a component of HP Web Based Management Products for Microsoft Windows NT 4.0, Windows 2000, and Windows 2003.

HP has addressed the following issues in HP HTTP Server version 5.96:
  • Incorporated a security enhancement to prevent malicious attacks on input parameters.
You can verify the version of HP HTTP Server by viewing the bottom left corner of the System Management Homepage. For some older versions, you will need to hover over the copyright line. HP strongly recommends that you update your software as soon as possible to remove these vulnerabilities.

Table of affected software Download patch


Advisory archive

All issues in these advisories have been addressed in the most recent releases of the affected software. Customers with current software may disregard these advisories.

» Potential Unauthorized File Access in Insight Diagnostics Online Edition (SSRT4918) [18 October 2004]
» HP Web Management Software Security Vulnerability (SSRT3632) [October 2003]
» HP Management Software Security Vulnerability (SSRT3499) [April 2003]
» HP Management Software Security Vulnerability (SSRT3516) [April 2003]
» HP Management Software Security Vulnerability (SSRT3521) [April 2003]
» HP Management Software Security Vulnerability (SSRT3530) [April 2003]
» Vulnerability in the Simple Network Management Protocol (SSRT2310c) [January 2003]
» Compaq Insight Manager XE Software Security Vulnerability (SSRT0766) [September 2001]
» Compaq management software security vulnerability (SSRT0758) [September 2001]
» Compaq Web-enabled Management Software Security Advisory Reference (SSRT0705) [January 2001]
» PFC User account Vulnerability in the Compaq Management Agents for Servers for Microsoft Windows NT [September 1999]
» Compaq Management Agents Security Advisory [June 1999]

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2008 Hewlett-Packard Development Company, L.P.
/* SiteCatalyst code version: CMA 20050829a */ /* Specify the Report Suite ID(s) to track here */