Lucene search

K
cve[email protected]CVE-2013-4836
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-4836

2022-10-0316:14:57
web.nvd.nist.gov
19
hp
alm
synchronizer
cve-2013-4836
vulnerability
soap
gossipservice
remote attackers
code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.9 High

AI Score

Confidence

Low

0.203 Low

EPSS

Percentile

96.4%

Unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component before 1.4.2 in HP Application LifeCycle Management (ALM) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1759.

Affected configurations

NVD
Node
hpalm_synchronizerRange1.41
OR
hpalm_synchronizerMatch1.10
OR
hpalm_synchronizerMatch1.20
OR
hpalm_synchronizerMatch1.30
OR
hpalm_synchronizerMatch1.40
AND
hpapplication_lifecycle_managementMatch-

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.9 High

AI Score

Confidence

Low

0.203 Low

EPSS

Percentile

96.4%

Related for CVE-2013-4836