Junglewise Threat Intelligence

CVE-2013-4810: HP Multiple Products Remote Code Execution Vulnerability

CVE-2013-4810 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: Hp, Hewlett Packard Enterprise.

Executive brief

HP ProCurve Manager, Identity Driven Manager, and Application Lifecycle Management are vulnerable to remote code execution. Attackers can execute arbitrary code by sending a marshalled object to the EJBInvokerServlet or JMXInvokerServlet.

Affected products

  • HP ProCurve Manager (PCM) 3.20, 4.0
  • HP PCM+ 3.20, 4.0
  • HP Identity Driven Manager (IDM) 4.0
  • HP Application Lifecycle Management -

Timeline

  • 2013-09-11: disclosed: ZDI advisory ZDI-13-229 published
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog