RULE(RULE ID:320515)

Rule General Information
Release Date: 2017-09-21
Rule Name: HPE Intelligent Management Center ictExpertDownload Expression Language Injection Vulnerability -1 (CVE-2017-12500)
Severity:
CVE ID:
Rule Protection Details
Description: An Expression Language injection vulnerability has been reported in HPE Intelligent Management Center. The vulnerability is due to insufficient handling of the beanName request parameter on ictExpertDownload.xhtml.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:100367
ExploitDB:44648
SecurityTrackerID:1039152
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03768en_us
Solutions
Applying the patch 7.3 E0506 is able to eliminate this problem.