First published: Fri Sep 13 2013(Updated: )
Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Identity Driven Manager | =4.0 | |
HP ProCurve Manager | =3.20 | |
Hewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management | =3.20 | |
HP ProCurve Manager | =4.0 | |
Hewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4809 is considered a medium-severity vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2013-4809, upgrade to the latest version of HP ProCurve Manager or Identity Driven Manager that resolves the SQL injection vulnerabilities.
CVE-2013-4809 affects HP ProCurve Manager versions 3.20 and 4.0, and Identity Driven Manager version 4.0.
CVE-2013-4809 is classified as an SQL injection vulnerability that allows execution of arbitrary SQL commands.
Yes, CVE-2013-4809 can be exploited remotely by attackers through malicious input to the affected parameters.