RULE(RULE ID:711275)

Rule General Information
Release Date: 2017-10-06
Rule Name: HPE Intelligent Management Center dbman RestoreDBase MySQL Command Injection Vulnerability (CVE-2017-5819)
Severity:
CVE ID:
Rule Protection Details
Description: A command injection vulnerability has been reported in the dbman component of HPE Intelligent Management Center. The vulnerability exists due to missing validation of user-provided parameters when handling RestoreDBase commands for MySQL databases.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Other Unix, Linux
Reference: CVE-2017-5819
Solutions
HPE has issued a fix (7.3 E0504P04). The HPE advisory is available at https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03745en_us