Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:HP-PROCURVE-FILE-UPLD-SSL

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

HP ProCurve Manager SNAC UpdateCertificatesServlet Code Execution (SSL)

Release Date

2013/10/07

Update Number

2307

Supported Platforms

idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: HP ProCurve Manager SNAC UpdateCertificatesServlet Code Execution (SSL)


This signature detects attempts to exploit a known vulnerability against HP ProCurve Manager. A successful attack can lead to arbitrary code execution.

Extended Description

UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

Affected Products

  • hp identity_driven_manager 4.0
  • hp procurve_manager 3.20 (:~~~plus~~)
  • hp procurve_manager 4.0 (:~~~plus~~)

References

  • CVE: CVE-2013-4812

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out