CVE-2013-4835

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:sitescope:10.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:10.13:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.10:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.12:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.20:*:*:*:*:*:*:*
cpe:2.3:a:hp:sitescope:11.21:*:*:*:*:*:*:*

History

21 Nov 2024, 01:56

Type Values Removed Values Added
References () http://www.exploit-db.com/exploits/30473 - () http://www.exploit-db.com/exploits/30473 -
References () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03969435 - Vendor Advisory () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03969435 - Vendor Advisory
References () https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03969435 - () https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03969435 -

Information

Published : 2013-11-04 16:55

Updated : 2024-11-21 01:56


NVD link : CVE-2013-4835

Mitre link : CVE-2013-4835

CVE.ORG link : CVE-2013-4835


JSON object : View

Products Affected

hp

  • sitescope