Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-2561

Опубликовано: 21 мая 2012
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary JSP code within the JBOSS Application Server component via a crafted request to TCP port 1098, 1099, or 4444.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hp:business_service_management:9.12:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02341
Низкий

10 Critical

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary JSP code within the JBOSS Application Server component via a crafted request to TCP port 1098, 1099, or 4444.

EPSS

Процентиль: 85%
0.02341
Низкий

10 Critical

CVSS2

Дефекты

CWE-264