Skip to main content

CVE-2009-4189

CVSS Score Not Available
83.49%
HIGH RiskEPSS (99th percentile)

HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3099 and CVE-2009-3843.

Published: 12/3/2009
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

83.49%HIGH Exploitation Risk
99th percentile

This vulnerability has a 83.49% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.