7.5

CVE-2013-4835

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpSitescope Version10.11
HpSitescope Version10.13
HpSitescope Version11.01
HpSitescope Version11.1
HpSitescope Version11.10
HpSitescope Version11.11
HpSitescope Version11.12
HpSitescope Version11.20
HpSitescope Version11.21
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 79.3% 0.99
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P