|
|||
Rule General Information |
---|
Release Date: | 2019-06-27 | |
Rule Name: | HP SiteScope 'issueSiebelCmd' SOAP Request Handling Authentication Bypass Vulnerability (CVE-2013-4835) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765. | |
Impact: | An attacker could exploit this vulnerability to have unspecified effect. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | ExploitDB:30473 https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03969435 https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03969435 |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03969435 |