Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:HPIM-SOM-EUACCNT-BYPASS

Severity

Medium

Recommended

Yes

Category

APP

Keywords

HP Intelligent Management Center SOM euAccountSerivce Authentication Bypass

Release Date

2013/11/20

Update Number

2321

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: HP Intelligent Management Center SOM euAccountSerivce Authentication Bypass


This signature detects a known authentication bypass vulnerability in the SOM add-in module of HP Intelligent Management Center. It is due to a lack of authentication in the euAccountSerivce (sic) servlet when processing HTTP request parameters. By sending crafted HTTP requests to the target system, a remote unauthenticated attacker can leverage this vulnerability to create a web administration account on a target system.

Extended Description

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.

Affected Products

  • hp intelligent_management_center
  • ibm imc_service_operation_management_software_module -

References

  • CVE: CVE-2013-4824
  • URL: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03943547

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out