The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CHP Helion Cloud Development Platform
APPHp1.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Powiązane podatności
CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)
CVE-2015-3113CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE w Adobe Flash Player — heap-based buffer overflow (CVE-2015-3113)
CVE-2013-4810CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE przez EJBInvokerServlet/JMXInvokerServlet w HP ProCurve Manager
CVE-2012-1823CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE w PHP-CGI poprzez wstrzyknięcie opcji wiersza poleceń
CVE-2005-2773CRITICAL9.8⚠ KEVPL ✓ten sam vendor
HP OpenView NNM – command injection przez shell metacharacters w parametrze node