Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4810

Опубликовано: 16 сент. 2013
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Высокий

Описание

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hp:application_lifecycle_management:-:*:*:*:*:*:*:*
cpe:2.3:a:hp:procurve_manager:3.20:*:*:*:-:*:*:*
cpe:2.3:a:hp:procurve_manager:3.20:*:*:*:plus:*:*:*
cpe:2.3:a:hp:procurve_manager:4.0:*:*:*:-:*:*:*
cpe:2.3:a:hp:procurve_manager:4.0:*:*:*:plus:*:*:*

EPSS

Процентиль: 99%
0.8588
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-94
CWE-94

Связанные уязвимости

redhat
больше 12 лет назад

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

CVSS3: 9.8
github
больше 3 лет назад

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

EPSS

Процентиль: 99%
0.8588
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-94
CWE-94