CVE Vulnerabilities

CVE-2013-4835

Published: Nov 04, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.

Affected Software

NameVendorStart VersionEnd Version
SitescopeHp10.11 (including)10.11 (including)
SitescopeHp10.13 (including)10.13 (including)
SitescopeHp11.01 (including)11.01 (including)
SitescopeHp11.1 (including)11.1 (including)
SitescopeHp11.10 (including)11.10 (including)
SitescopeHp11.11 (including)11.11 (including)
SitescopeHp11.12 (including)11.12 (including)
SitescopeHp11.20 (including)11.20 (including)
SitescopeHp11.21 (including)11.21 (including)

References