CVE-2013-4835: High severity hp sitescope vulnerability
Published Nov 4, 2013
·Updated
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.
Affected Software
9 affected components
HP SiteScope=10.11
HP SiteScope=10.13
HP SiteScope=11.01
HP SiteScope=11.1
HP SiteScope=11.10
HP SiteScope=11.11
HP SiteScope=11.12
HP SiteScope=11.20
HP SiteScope=11.21
Event History
Nov 4, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4835?
CVE-2013-4835 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2013-4835?
To fix CVE-2013-4835, upgrade to HP SiteScope version 11.22 or later, which contains the necessary security patch.
3
What does CVE-2013-4835 exploit?
CVE-2013-4835 exploits the APISiteScopeImpl SOAP service allowing remote attackers to bypass authentication.
4
Which versions of HP SiteScope are affected by CVE-2013-4835?
CVE-2013-4835 affects HP SiteScope versions 10.11, 10.13, 11.01, 11.1, 11.10, 11.11, 11.12, 11.20, and 11.21.
5
Can CVE-2013-4835 be exploited remotely?
Yes, CVE-2013-4835 can be exploited remotely, allowing attackers to execute arbitrary code.