Remote Code Execution Vulnerability in HP ProCurve Manager and IDM
CVE-2013-4812
Currently unrated
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 16 September 2013
What is CVE-2013-4812?
The UpdateCertificatesServlet in HP ProCurve Manager (PCM) and Identity Driven Manager (IDM) fails to adequately validate the fileName argument, which allows attackers to upload potentially malicious .jsp files. This vulnerability enables attackers to execute arbitrary code on the affected server, leading to severe security risks. Systems running HP ProCurve Manager versions 3.20 and 4.0, as well as the PCM+ variant and IDM 4.0, are susceptible to exploitation. Regular updates and following security advisories are essential to mitigate these risks.