Remote Code Execution Vulnerability in HP ProCurve Manager and IDM
CVE-2013-4812
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 16 September 2013
What is CVE-2013-4812?
The UpdateCertificatesServlet in HP ProCurve Manager (PCM) and Identity Driven Manager (IDM) fails to adequately validate the fileName argument, which allows attackers to upload potentially malicious .jsp files. This vulnerability enables attackers to execute arbitrary code on the affected server, leading to severe security risks. Systems running HP ProCurve Manager versions 3.20 and 4.0, as well as the PCM+ variant and IDM 4.0, are susceptible to exploitation. Regular updates and following security advisories are essential to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
73% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved