Vulnerability record · CVE-2011-0276 · published 2 February 2011
CVE-2011-0276: HP OpenView Performance Insight hidden account allows remote code execution
Hp · Openview Performance Insight
HP OpenView Performance Insight Server versions 5.2 through 5.41 contains a hidden account in the com.trinagy.security.XMLUserManager Java class. The doPost method in com.trinagy.servlet.HelpManagerServlet can be reached remotely and used to execute arbitrary code. This is a full-impact, unauthenticated remote code execution flaw in a server product.
Description
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with CVSS 10 and a public exploit makes this an urgent patching priority despite the age of the CVE.
What it is
HP OpenView Performance Insight Server versions 5.2 through 5.41 contains a hidden account in the com.trinagy.security.XMLUserManager Java class. The doPost method in com.trinagy.servlet.HelpManagerServlet can be reached remotely and used to execute arbitrary code. This is a full-impact, unauthenticated remote code execution flaw in a server product.
Impact
A remote attacker can execute arbitrary code with the privileges of the affected server process, leading to complete compromise of confidentiality, integrity and availability. No credentials are required.
Attack surface
The flaw is reachable over the network through the HelpManagerServlet doPost method, per the CVSS vector AV:N/AC:L/Au:N. No authentication or user interaction is needed.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.82426 (99.6th percentile) and a public Exploit-DB entry (16984) exists, indicating known exploit code is available.
What to do
- Apply the HP vendor advisory fix for OpenView Performance Insight Server (objectID c02695453) or upgrade to a supported release.
- If patching is not possible, restrict network access to the HelpManagerServlet and the affected server ports to trusted management hosts only.
- Remove or disable the hidden account in com.trinagy.security.XMLUserManager if the product allows it.
- Monitor and log access to the HelpManagerServlet endpoint for unexpected POST requests.
Detection
- Inspect web server and application logs for POST requests to the HelpManagerServlet path, especially from untrusted sources.
- Alert on unexpected child processes or command execution spawned by the OpenView Performance Insight Java process.
- Review authentication logs for use of the hidden account in XMLUserManager.
- Use network monitoring to detect anomalous traffic to the OpenView Performance Insight server management interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0276 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0276), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.