|
|||
Rule General Information |
---|
Release Date: | 2017-09-21 | |
Rule Name: | HPE Intelligent Management Center ictExpertDownload Expression Language Injection Vulnerability -1 (CVE-2017-12500) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | An Expression Language injection vulnerability has been reported in HPE Intelligent Management Center. The vulnerability is due to insufficient handling of the beanName request parameter on ictExpertDownload.xhtml. | |
Impact: | An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Other Unix, FreeBSD, Linux | |
Reference: | SecurityFocusBID:100367 ExploitDB:44648 SecurityTrackerID:1039152 https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03768en_us |
|
Solutions |
---|
Applying the patch 7.3 E0506 is able to eliminate this problem. |