Lucene search

K
cvelistMitreCVELIST:CVE-2009-4188
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-4188

2022-10-0316:24:01
mitre
www.cve.org
hp operations dashboard
default password
remote code execution
manager role
file upload
tomcat.

7.7 High

AI Score

Confidence

Low

0.296 Low

EPSS

Percentile

96.9%

HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3098.

7.7 High

AI Score

Confidence

Low

0.296 Low

EPSS

Percentile

96.9%

Related for CVELIST:CVE-2009-4188