Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:UNIVERSAL-CMDB-AXIS2-RCE

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

HP Universal CMDB Server Axis2 Default Credentials Remote Code Execution

Release Date

2011/07/21

Update Number

1959

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: HP Universal CMDB Server Axis2 Default Credentials Remote Code Execution


This signature detects attempts to exploit a known vulnerability in HP Universal CMDB Server. The vulnerability is due to an authentication weakness in the product's configuration. When the software is installed, default credentials are assigned to the Axis2 web services component. A remote attacker can leverage this vulnerability to upload a malicious web service to a target system, enabling arbitrary code execution within the security context of an Axis2 web service.

References

  • BugTraq: 68363
  • CVE: CVE-2014-2617
  • URL: http://retrogod.altervista.org/9sg_ca_d2d.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out