vendor:
System Management
by:
agix
N/A
CVSS
N/A
Remote Code Execution
N/A
CWE
Product Name: System Management
Affected Version From: HP System Management 7.1.1
Affected Version To: HP System Management 6.3.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux (CentOS)
2012
HP System Management Anonymous Access Code Execution
This module exploits an anonymous remote code execution on HP System Management 7.1.1 and earlier. The vulnerability exists when handling the iprange parameter on a request against /proxy/DataValidation. In order to work HP System Management must be configured with Anonymous access enabled.
Mitigation:
Configure HP System Management with Anonymous access disabled.