- Description
- HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.
- Source
- hp-security-alert@hp.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Data from CISA
- Vulnerability name
- HP Multiple Products Remote Code Execution Vulnerability
- Exploit added on
- Mar 25, 2022
- Exploit action due
- Apr 15, 2022
- Required action
- Apply updates per vendor instructions.
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hp:application_lifecycle_management:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5B01474-2B07-4448-8265-6F3189697B5E"
},
{
"criteria": "cpe:2.3:a:hp:procurve_manager:3.20:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A2CD0AC-7ED5-4C0C-8E2C-2A4531AC8A8E"
},
{
"criteria": "cpe:2.3:a:hp:procurve_manager:3.20:*:*:*:plus:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FEC5FF99-76CE-4525-B6B5-039762AC9425"
},
{
"criteria": "cpe:2.3:a:hp:procurve_manager:4.0:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D39541A2-B3DF-4A56-84C8-00FC1CB2CEA9"
},
{
"criteria": "cpe:2.3:a:hp:procurve_manager:4.0:*:*:*:plus:*:*:*",
"vulnerable": true,
"matchCriteriaId": "374C81F8-DCA4-4C66-A300-94785F228E06"
}
],
"operator": "OR"
}
]
}
]