CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
97.5%
HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1 do not require authentication for JBoss RMI requests, which allows remote attackers to execute arbitrary code by (1) uploading this code within an archive or (2) instantiating a class.
Vendor | Product | Version | CPE |
---|---|---|---|
hp | tippingpoint_security_management_system | * | cpe:2.3:a:hp:tippingpoint_security_management_system:*:*:*:*:*:*:*:* |
hp | tippingpoint_virtual_security_management_system | * | cpe:2.3:a:hp:tippingpoint_virtual_security_management_system:*:*:*:*:*:*:*:* |