CISA Known Exploited Vulnerability

CVE-2013-4810

Hewlett Packard (HP) · ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management

HP Multiple Products Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-94
Ransomware Unknown

CISA description

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

Required action

Apply updates per vendor instructions.