Remote Code Execution Vulnerability in HP ProCurve Manager and IDM
CVE-2013-4812
Currently unrated
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 16 September 2013
Summary
The UpdateCertificatesServlet in HP ProCurve Manager (PCM) and Identity Driven Manager (IDM) fails to adequately validate the fileName argument, which allows attackers to upload potentially malicious .jsp files. This vulnerability enables attackers to execute arbitrary code on the affected server, leading to severe security risks. Systems running HP ProCurve Manager versions 3.20 and 4.0, as well as the PCM+ variant and IDM 4.0, are susceptible to exploitation. Regular updates and following security advisories are essential to mitigate these risks.
References
EPSS Score
68% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved