vendor:
IMC (Intelligent Management Center)
by:
Raphael Kuhn
7,5
CVSS
HIGH
Java Deserialization
502
CWE
Product Name: IMC (Intelligent Management Center)
Affected Version From: HPE/H3C IMC (Intelligent Management Center) Java 1.8.0_91
Affected Version To: HPE/H3C IMC (Intelligent Management Center) Java 1.8.0_91
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2008 R2
2018
HPE/H3C IMC – Java Deserialization Exploit
This exploit is based on a Java deserialization vulnerability in HPE/H3C IMC (Intelligent Management Center). It allows an attacker to execute arbitrary commands on the target system by sending a specially crafted request to the server. The exploit can be used with either a binary payload file or a string payload.
Mitigation:
Disable Java deserialization on the server, or upgrade to a version that is not vulnerable.