Unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component before 1.4.2 in HP Application LifeCycle Management (ALM) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1759.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PHP Alm Synchronizer
APPHp1.101.201.301.40≤ 1.41HP Application Lifecycle Management
APPHpwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
Powiązane podatności
CVE-2013-4810CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE przez EJBInvokerServlet/JMXInvokerServlet w HP ProCurve Manager
CVE-2013-4834HIGH7.5ten sam produkt
Unspecified vulnerability in the client component in HP Application LifeCycle Management (ALM) before 11 p11 a...
CVE-2014-2631MEDIUM4.6ten sam produkt
Unspecified vulnerability in HP Application Lifecycle Management (aka Quality Center) 11.5x and 12.0x allows l...
CVE-2013-4802MEDIUM4.3ten sam produkt
Cross-site scripting (XSS) vulnerability in HP Application Lifecycle Management (ALM) Quality Center before 11...
CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)