KhiZaRix Posted March 18, 2015 Report Posted March 18, 2015 HP Security Bulletin HPSBST03298 1 - Potential security vulnerabilities have been identified with HP XP Service Processor Software for Windows. These vulnerabilities could be exploited resulting in a variety of outcomes. Code:-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1Note: the current version of the following document is available here:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04600552SUPPORT COMMUNICATION - SECURITY BULLETINDocument ID: c04600552Version: 1HPSBST03298 rev.1 - HP XP Service Processor Software for Windows, MultipleVulnerabilitiesNOTICE: The information in this Security Bulletin should be acted upon assoon as possible.Release Date: 2015-03-13Last Updated: 2015-03-13- ------------------------------------------------------------------------------ ---Potential Security Impact: Multiple vulnerabilitiesSource: Hewlett-Packard Company, HP Software Security Response TeamVULNERABILITY SUMMARYPotential security vulnerabilities have been identified with HP XP ServiceProcessor Software for Windows. These vulnerabilities could be exploitedresulting in a variety of outcomes.References:SSRT101826SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.The following HP XP Service Processor Software for Windows is affected:HP XP7HP XP10000HP XP12000HP XP20000HP XP24000HP XP P9500BACKGROUNDFor a PGP signed version of this security bulletin please write to:security-alert@hp.comMicrosoft has published Security Information Bulletins since January 2009.This bulletin presents all of the necessary patches and updates for HP XPService Processor Software in a cummulative format. This information isupdated monthly.Updating the HP XP Service Processor Software can be performed withoutinterference or distruption to data flow on the XP product.RESOLUTIONHP has made a web-based spread sheet available which lists all updates to theHP XP Service Processor Software that runs on the Microsoft Windows OperatingSystem.The OS versions include Windows 7, Window Vista (64 and 32 bit) and WindowsXP.The document may be downloaded from here: HP Insight Management - OverviewIn this HP Enterprise Information LIbrary ,Select 'Storage' at the top,In the 'Products and Solutions' column, select 'XP Storage',In the 'Information Type' column, select only 'Service and Maintenance'.The HP XP Service Processor (SVP) OS Security Patch Summary Sheet may bedownloaded to your desktop.HISTORYVersion:1 (rev.1) - 13 March 2015 Initial releaseThird Party Security Patches: Third party security patches that are to beinstalled on systems running HP software products should be applied inaccordance with the customer's patch management policy.Support: For issues about implementing the recommendations of this SecurityBulletin, contact normal HP Services support channel. For other issues aboutthe content of this Security Bulletin, send e-mail to security-alert@hp.com.Report: To report a potential security vulnerability with any HP supportedproduct, send Email to: security-alert@hp.comSubscribe: To initiate a subscription to receive future HP Security Bulletinalerts via Email:HP: Subscribe todaySecurity Bulletin Archive: A list of recently released Security Bulletins isavailable here:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/Software Product Category: The Software Product Category is represented inthe title by the two characters following HPSB.3C = 3COM3P = 3rd Party SoftwareGN = HP General SoftwareHF = HP Hardware and FirmwareMP = MPE/iXMU = Multi-Platform SoftwareNS = NonStop ServersOV = OpenVMSPI = Printing and ImagingPV = ProCurveST = Storage SoftwareTU = Tru64 UNIXUX = HP-UXCopyright 2015 Hewlett-Packard Development Company, L.P.Hewlett-Packard Company shall not be liable for technical or editorial errorsor omissions contained herein. The information provided is provided "as is"without warranty of any kind. To the extent permitted by law, neither HP orits affiliates, subcontractors or suppliers will be liable forincidental,special or consequential damages including downtime cost; lostprofits; damages relating to the procurement of substitute products orservices; or damages for loss of data, or software restoration. Theinformation in this document is subject to change without notice.Hewlett-Packard Company and the names of Hewlett-Packard products referencedherein are trademarks of Hewlett-Packard Company in the United States andother countries. Other product and company names mentioned here in may betrademarks of their respective owners.-----BEGIN PGP SIGNATURE-----Version: GnuPG v1.4.13 (GNU/Linux)iEYEARECAAYFAlUHov8ACgkQ4B86/C0qfVnbrgCg4oVyYhIvPf8/mkS/IwjWrMRgblEAn3uS87tqYInkFZtz8QNOjlVcU7l0=6XaT-----END PGP SIGNATURE-----Source: http://dl.packetstormsecurity.net/1503-advisories/HPSBST03298-1.txt 1 Quote