The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CHP Helion Cloud Development Platform
APPHp1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)
CVE-2015-3113CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w Adobe Flash Player — heap-based buffer overflow (CVE-2015-3113)
CVE-2013-4810CRITICAL9.8⚠ KEVPL ✓same vendor
RCE przez EJBInvokerServlet/JMXInvokerServlet w HP ProCurve Manager
CVE-2012-1823CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w PHP-CGI poprzez wstrzyknięcie opcji wiersza poleceń
CVE-2005-2773CRITICAL9.8⚠ KEVPL ✓same vendor
HP OpenView NNM – command injection przez shell metacharacters w parametrze node