Unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component before 1.4.2 in HP Application LifeCycle Management (ALM) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1759.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PHP Alm Synchronizer
APPHp1.101.201.301.40≤ 1.41HP Application Lifecycle Management
APPHpall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2013-4810CRITICAL9.8⚠ KEVPL ✓same product
RCE przez EJBInvokerServlet/JMXInvokerServlet w HP ProCurve Manager
CVE-2013-4834HIGH7.5same product
Unspecified vulnerability in the client component in HP Application LifeCycle Management (ALM) before 11 p11 a...
CVE-2014-2631MEDIUM4.6same product
Unspecified vulnerability in HP Application Lifecycle Management (aka Quality Center) 11.5x and 12.0x allows l...
CVE-2013-4802MEDIUM4.3same product
Cross-site scripting (XSS) vulnerability in HP Application Lifecycle Management (ALM) Quality Center before 11...
CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)