ID

VAR-201710-0237


CVE

CVE-2017-5789


TITLE

HP LoadRunner/Performance Center Heap Buffer Overflow Vulnerability

Trust: 0.8

sources: IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e // CNVD: CNVD-2017-03832

DESCRIPTION

HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified vectors. At least in LoadRunner, this is a libxdrutil.dll mxdr_string heap-based buffer overflow. HPE LoadRunner and Performance Center Contains an access control vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Authentication is not required to exploit this vulnerability. The specific flaw exists within the libxdrutil.dll mxdr_string method. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the current process. HP Intelligent Management Center (iMC) is a network intelligent management center solution from Hewlett Packard (HP). A remote heap buffer overflow vulnerability exists in HP LoadRunner/Performance Center that was caused by insufficient boundary checking before copying user data to a memory buffer of insufficient size. A failed attack can result in a denial of service. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03712en_us SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: hpesbgn03712en_us Version: 1 HPESBGN03712 rev.1 - HPE LoadRunner and Performance Center, Remote Code Execution NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. Release Date: 2017-03-07 Last Updated: 2017-03-07 Potential Security Impact: Remote: Code Execution Source: Hewlett Packard Enterprise, Product Security Response Team VULNERABILITY SUMMARY A potential security vulnerability has been identified in HPE LoadRunner and Performance Center. References: - CVE-2017-5789 - Remote Code Execution SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. - HPE LoadRunner - v12.53.0 and earlier - HPE Performance Center - v12.53.0 and earlier BACKGROUND CVSS Base Metrics ================= Reference, CVSS V3 Score/Vector, CVSS V2 Score/Vector CVE-2017-5789 7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) Information on CVSS is documented in HPE Customer Notice HPSN-2008-002 here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c01345499 Hewlett Packard Enterprise thanks Tenable Network Security working with Trend Micro's Zero Day Initiative (ZDI) for reporting this issue to security-alert@hpe.com RESOLUTION HPE has provided the following software updates to resolve the vulnerability in the impacted versions of HPE LoadRunner and Performance Center. **LoadRunner** - Please download and install v12.53 Patch 4 using following links: * LoadRunner Full: <https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets arch/document/LID/LR_03639> * Load Generator SA: <https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets arch/document/LID/LRLG_00131> * VuGen SA: <https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets arch/document/LID/LRVUG_00214> * Analysis SA: <https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets arch/document/LID/LRANLSYS_00110> * TruClient SA: <https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets arch/document/LID/LRTC_00005> Release notes for the LoadRunner patch is available at: <https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets arch/document/KM02688589> **Performance Center** - Please download and install v12.53 Patch 4 using following link: * Performance Center Server and Host: <https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets arch/document/LID/PC_00312> Release notes for the Performance Center patch is available at: <https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets arch/document/KM02690789> HISTORY Version:1 (rev.1) - 7 March 2017 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running Hewlett Packard Enterprise (HPE) software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HPE Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hpe.com. Report: To report a potential security vulnerability for any HPE supported product: Web form: https://www.hpe.com/info/report-security-vulnerability Email: security-alert@hpe.com Subscribe: To initiate a subscription to receive future HPE Security Bulletin alerts via Email: http://www.hpe.com/support/Subscriber_Choice Security Bulletin Archive: A list of recently released Security Bulletins is available here: http://www.hpe.com/support/Security_Bulletin_Archive Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HPE General Software HF = HPE Hardware and Firmware MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PV = ProCurve ST = Storage Software UX = HP-UX Copyright 2016 Hewlett Packard Enterprise Hewlett Packard Enterprise shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett Packard Enterprise and the names of Hewlett Packard Enterprise products referenced herein are trademarks of Hewlett Packard Enterprise in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBCAAGBQJYvySUAAoJELXhAxt7SZai2r4H+wSohWbdWZfY+1GVhhXcJhoI 9PrgkcoW6Bo2tJI8JCveAKrpJWqzXhx77zPb94Bf8ER3KyUiFTOhx/z5Kv2cW2a3 MswkriLaMzi1G8cihlmtqmTRFfrNn5AJZSOPKR12iuRgpUEnkxTf3727SKrp25uv 1ZD8xXigrEiF3i5KnXR4UJGzv8LZjcwv5ClO13SysR8oTBa0UTKIrvN9s6wkyIEX cMV9BWFknvuC4Nh2lo6uXWqT5mc8Ur5Z1XMMbP9AdVsqd4O1RC70BXBDJ7fvg6qb 0TsnnxyUi40ZqC3DxpFgOdxe0veWZ41wIpVypgyoD78QVi2AbGRDAV6l0R75zgg= =VjbZ -----END PGP SIGNATURE-----

Trust: 3.33

sources: NVD: CVE-2017-5789 // JVNDB: JVNDB-2017-009402 // ZDI: ZDI-17-160 // CNVD: CNVD-2017-03832 // BID: 96774 // IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e // PACKETSTORM: 141557

IOT TAXONOMY

category:['IoT', 'ICS']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e // CNVD: CNVD-2017-03832

AFFECTED PRODUCTS

vendor:hpmodel:performance centerscope:lteversion:12.53

Trust: 1.0

vendor:hpmodel:loadrunnerscope:lteversion:12.53

Trust: 1.0

vendor:hpmodel:performance centerscope:eqversion:12.53

Trust: 0.9

vendor:hpmodel:loadrunnerscope:eqversion:12.53

Trust: 0.9

vendor:hewlett packardmodel:hpe loadrunnerscope:ltversion:12.53 patch 4

Trust: 0.8

vendor:hewlett packardmodel:hpe performance centerscope:ltversion:12.53 patch 4

Trust: 0.8

vendor:hewlett packardmodel:loadrunnerscope: - version: -

Trust: 0.7

vendor:hpmodel:loadrunnerscope:lteversion:<=12.53.0

Trust: 0.6

vendor:hpmodel:performance centerscope:lteversion:<=12.53.0

Trust: 0.6

vendor:hpmodel:performance center patchscope:eqversion:12.501

Trust: 0.3

vendor:hpmodel:performance centerscope:eqversion:12.50

Trust: 0.3

vendor:hpmodel:performance center patchscope:eqversion:12.202

Trust: 0.3

vendor:hpmodel:performance centerscope:eqversion:12.20

Trust: 0.3

vendor:hpmodel:performance center patchscope:eqversion:12.013

Trust: 0.3

vendor:hpmodel:performance centerscope:eqversion:12.01

Trust: 0.3

vendor:hpmodel:performance centerscope:eqversion:12.00

Trust: 0.3

vendor:hpmodel:performance center patchscope:eqversion:12.01

Trust: 0.3

vendor:hpmodel:performance centerscope:eqversion:12.0

Trust: 0.3

vendor:hpmodel:performance center patchscope:eqversion:11.523

Trust: 0.3

vendor:hpmodel:performance centerscope:eqversion:11.52

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:11.52.1

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:9.1

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:9.0.0.0

Trust: 0.3

vendor:hpmodel:loadrunner buildscope:eqversion:8.1.0.01735

Trust: 0.3

vendor:hpmodel:loadrunner patchscope:eqversion:12.503

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:12.50

Trust: 0.3

vendor:hpmodel:loadrunner patchscope:eqversion:12.022

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:12.02

Trust: 0.3

vendor:hpmodel:loadrunner patchscope:eqversion:12.013

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:12.01

Trust: 0.3

vendor:hpmodel:loadrunner patchscope:eqversion:12.01

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:12.0

Trust: 0.3

vendor:hpmodel:loadrunner patchscope:eqversion:11.523

Trust: 0.3

vendor:hpmodel:loadrunner patchscope:eqversion:11.522

Trust: 0.3

vendor:hpmodel:loadrunner patchscope:eqversion:11.521

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:11.52

Trust: 0.3

vendor:hpmodel:loadrunner patch4scope:eqversion:11.0

Trust: 0.3

vendor:hpmodel:loadrunnerscope:eqversion:11.0

Trust: 0.3

vendor:hpmodel:performance center patchscope:neversion:12.534

Trust: 0.3

vendor:hpmodel:loadrunner patchscope:neversion:12.534

Trust: 0.3

vendor:loadrunnermodel: - scope:eqversion:*

Trust: 0.2

vendor:performance centermodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e // ZDI: ZDI-17-160 // CNVD: CNVD-2017-03832 // BID: 96774 // JVNDB: JVNDB-2017-009402 // CNNVD: CNNVD-201703-484 // NVD: CVE-2017-5789

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-5789
value: CRITICAL

Trust: 1.0

NVD: CVE-2017-5789
value: CRITICAL

Trust: 0.8

ZDI: CVE-2017-5789
value: MEDIUM

Trust: 0.7

CNVD: CNVD-2017-03832
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201703-484
value: CRITICAL

Trust: 0.6

IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e
value: CRITICAL

Trust: 0.2

nvd@nist.gov: CVE-2017-5789
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

ZDI: CVE-2017-5789
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.7

CNVD: CNVD-2017-03832
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

nvd@nist.gov: CVE-2017-5789
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e // ZDI: ZDI-17-160 // CNVD: CNVD-2017-03832 // JVNDB: JVNDB-2017-009402 // CNNVD: CNNVD-201703-484 // NVD: CVE-2017-5789

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.0

problemtype:CWE-284

Trust: 0.8

sources: JVNDB: JVNDB-2017-009402 // NVD: CVE-2017-5789

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 141557 // CNNVD: CNNVD-201703-484

TYPE

Buffer error

Trust: 0.8

sources: IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e // CNNVD: CNNVD-201703-484

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-009402

PATCH

title:HPESBGN03712url:https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03712en_us

Trust: 0.8

title:Hewlett Packard Enterprise has issued an update to correct this vulnerability.url:https://h20565.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03712en_us

Trust: 0.7

title:Patch for HP LoadRunner/Performance Center heap buffer overflow vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/91449

Trust: 0.6

title:HP LoadRunner and Performance Center Buffer error vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=68349

Trust: 0.6

sources: ZDI: ZDI-17-160 // CNVD: CNVD-2017-03832 // JVNDB: JVNDB-2017-009402 // CNNVD: CNNVD-201703-484

EXTERNAL IDS

db:NVDid:CVE-2017-5789

Trust: 4.3

db:ZDIid:ZDI-17-160

Trust: 2.6

db:BIDid:96774

Trust: 2.5

db:SECTRACKid:1038028

Trust: 1.6

db:SECTRACKid:1038029

Trust: 1.6

db:TENABLEid:TRA-2017-13

Trust: 1.6

db:BIDid:101224

Trust: 1.6

db:CNVDid:CNVD-2017-03832

Trust: 0.8

db:CNNVDid:CNNVD-201703-484

Trust: 0.8

db:JVNDBid:JVNDB-2017-009402

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-3933

Trust: 0.7

db:NSFOCUSid:36060

Trust: 0.6

db:IVDid:80B8FD74-085F-4BA1-8F15-8184E2CD860E

Trust: 0.2

db:PACKETSTORMid:141557

Trust: 0.1

sources: IVD: 80b8fd74-085f-4ba1-8f15-8184e2cd860e // ZDI: ZDI-17-160 // CNVD: CNVD-2017-03832 // BID: 96774 // JVNDB: JVNDB-2017-009402 // PACKETSTORM: 141557 // CNNVD: CNNVD-201703-484 // NVD: CVE-2017-5789

REFERENCES

url:http://www.securityfocus.com/bid/96774

Trust: 2.2

url:http://www.zerodayinitiative.com/advisories/zdi-17-160/

Trust: 1.9

url:http://www.securitytracker.com/id/1038029

Trust: 1.6

url:http://www.securitytracker.com/id/1038028

Trust: 1.6

url:https://h20566.www2.hpe.com/hpsc/doc/public/display?doclocale=en_us&docid=emr_na-hpesbgn03712en_us

Trust: 1.6

url:https://www.tenable.com/security/research/tra-2017-13

Trust: 1.6

url:http://www.securityfocus.com/bid/101224

Trust: 1.6

url:https://h20565.www2.hpe.com/hpsc/doc/public/display?docid=emr_na-hpesbgn03712en_us

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2017-5789

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-5789

Trust: 0.8

url:http://www.nsfocus.net/vulndb/36060

Trust: 0.6

url:http://www.hp.com

Trust: 0.3

url:https://h20564.www2.hpe.com/hpsc/doc/public/display?docid=emr_na-hpesbgn03712en_us

Trust: 0.1

url:https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facets

Trust: 0.1

url:http://www.hpe.com/support/security_bulletin_archive

Trust: 0.1

url:https://www.hpe.com/info/report-security-vulnerability

Trust: 0.1

url:http://www.hpe.com/support/subscriber_choice

Trust: 0.1

url:https://h20564.www2.hpe.com/hpsc/doc/public/display?docid=emr_na-c01345499

Trust: 0.1

sources: ZDI: ZDI-17-160 // CNVD: CNVD-2017-03832 // BID: 96774 // JVNDB: JVNDB-2017-009402 // PACKETSTORM: 141557 // CNNVD: CNNVD-201703-484 // NVD: CVE-2017-5789

CREDITS

Tenable Network Security

Trust: 1.6

sources: ZDI: ZDI-17-160 // BID: 96774 // CNNVD: CNNVD-201703-484

SOURCES

db:IVDid:80b8fd74-085f-4ba1-8f15-8184e2cd860e
db:ZDIid:ZDI-17-160
db:CNVDid:CNVD-2017-03832
db:BIDid:96774
db:JVNDBid:JVNDB-2017-009402
db:PACKETSTORMid:141557
db:CNNVDid:CNNVD-201703-484
db:NVDid:CVE-2017-5789

LAST UPDATE DATE

2025-04-20T23:23:35.547000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-17-160date:2017-03-09T00:00:00
db:CNVDid:CNVD-2017-03832date:2017-04-02T00:00:00
db:BIDid:96774date:2017-03-16T01:01:00
db:JVNDBid:JVNDB-2017-009402date:2017-11-10T00:00:00
db:CNNVDid:CNNVD-201703-484date:2019-10-23T00:00:00
db:NVDid:CVE-2017-5789date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:IVDid:80b8fd74-085f-4ba1-8f15-8184e2cd860edate:2017-04-02T00:00:00
db:ZDIid:ZDI-17-160date:2017-03-09T00:00:00
db:CNVDid:CNVD-2017-03832date:2017-04-02T00:00:00
db:BIDid:96774date:2017-03-10T00:00:00
db:JVNDBid:JVNDB-2017-009402date:2017-11-10T00:00:00
db:PACKETSTORMid:141557date:2017-03-09T17:02:19
db:CNNVDid:CNNVD-201703-484date:2017-03-13T00:00:00
db:NVDid:CVE-2017-5789date:2017-10-11T21:29:00.213