HIGH🇵🇱 Wersja polska

CVE-2013-4812

CVSS 10.0v2.0pub. 2013-09-16upd. 2026-04-29

UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • HP Identity Driven Manager

    APP
    Hp
    4.0
  • HP Procurve Manager

    APP
    Hp
    3.204.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2013-4810CRITICAL9.8⚠ KEVPL ✓same product

RCE przez EJBInvokerServlet/JMXInvokerServlet w HP ProCurve Manager

CVE-2013-4809HIGH7.5same product

Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.2...

CVE-2013-4811HIGH10.0same product

UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ ...

CVE-2013-4813HIGH10.0same product

The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Iden...

CVE-2007-4514MEDIUM5.0same product

Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote at...