First published: Mon Feb 24 2014(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote attackers to hijack the authentication of unspecified victims for requests that (1) insert XSS sequences or (2) execute arbitrary code.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Service Manager | =9.30 | |
HP Service Manager | =9.31 | |
HP Service Manager | =9.32 | |
HP Service Manager | =9.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6202 is considered a high-severity vulnerability due to its potential to allow remote attackers to hijack user authentication.
To fix CVE-2013-6202, it is recommended to update HP Service Manager to the latest version where the vulnerabilities are patched.
The potential impacts of CVE-2013-6202 include unauthorized execution of arbitrary code and the insertion of malicious XSS sequences.
The affected versions of HP Service Manager include 9.30, 9.31, 9.32, and 9.33.
Yes, CVE-2013-6202 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.